Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-0821. PoCs published by x128.
AI-analyzed exploit summary This exploit targets a SQL injection vulnerability in bxcp 0.299, allowing an attacker to dump user credentials (nickname and password) via a UNION-based SQLi attack. The script uses cURL to send a malicious request and saves the response to a file.
Description
SQL injection vulnerability in index.php in BXCP 0.299 allows remote attackers to execute arbitrary SQL commands via the tid parameter.
Exploits (1)
This exploit targets a SQL injection vulnerability in bxcp 0.299, allowing an attacker to dump user credentials (nickname and password) via a UNION-based SQLi attack. The script uses cURL to send a malicious request and saves the response to a file.