CVE-2006-1007
N8cms 1.1 and 1.2 - SQL Injection via dir and page_id Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-1007. PoCs published by Liz0ziM.
AI-analyzed exploit summary The provided text describes SQL injection vulnerabilities in the 'n8cms' script due to improper input sanitization. It outlines potential attack vectors via the 'dir' and 'page_id' parameters but does not include executable exploit code.
Description
Multiple SQL injection vulnerabilities in N8cms 1.1 and 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) dir and (2) page_id parameter to index.php.
Exploits (1)
The provided text describes SQL injection vulnerabilities in the 'n8cms' script due to improper input sanitization. It outlines potential attack vectors via the 'dir' and 'page_id' parameters but does not include executable exploit code.