CVE-2006-0462
AndoNET Blog 2004.09.02 - SQL Injection via Entrada Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-0462. PoCs published by Aliaksandr Hartsuyeu.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in AndoNET Blog by injecting a UNION-based SQL query via the 'entrada' parameter. The payload retrieves arbitrary data from the database by appending additional columns to the original query.
Description
SQL injection vulnerability in comentarios.php in AndoNET Blog 2004.09.02 allows remote attackers to execute arbitrary SQL commands via the entrada parameter.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in AndoNET Blog by injecting a UNION-based SQL query via the 'entrada' parameter. The payload retrieves arbitrary data from the database by appending additional columns to the original query.