CVE-2006-1112
Aztek Forum 4.0 - Information Disclosure via Long Login Value
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-1112. PoCs published by lorenzo.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in AZTEK forums 4.0, including XSS via crafted input in the 'Citer' function, SQL injection via a malformed 'msg' parameter, and a MySQL error-based information leak through unvalidated user registration. The PoC includes specific payloads and steps to trigger these issues.
Description
Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a long login value in a register form, which displays the installation path in a MySQL error message.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in AZTEK forums 4.0, including XSS via crafted input in the 'Citer' function, SQL injection via a malformed 'msg' parameter, and a MySQL error-based information leak through unvalidated user registration. The PoC includes specific payloads and steps to trigger these issues.