Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-0961. PoCs published by nukedx.
AI-analyzed exploit summary This Perl script exploits an SQL injection vulnerability in CilemNews System <= 1.1 via the 'haber_id' parameter in 'yazdir.asp'. It extracts admin credentials by injecting a UNION-based SQL query and displays them to the attacker.
Description
SQL injection vulnerability in yazdir.asp in Cilem Hiber 1.1 allows remote attackers to execute arbitrary SQL commands via the haber_id parameter. NOTE: this product has also been referred to as "Cilem News," although that does not appear to be the proper name.
Exploits (1)
This Perl script exploits an SQL injection vulnerability in CilemNews System <= 1.1 via the 'haber_id' parameter in 'yazdir.asp'. It extracts admin credentials by injecting a UNION-based SQL query and displays them to the attacker.