CVE-2006-1420
SaphpLesson 2.0 - SQL Injection via print.php lessid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-1420. PoCs published by Linux_Drox.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in SaphpLesson by injecting a UNION-based query to extract sensitive data (ModName and ModPassword) from the 'modretor' table. The attack leverages unsanitized input in the 'lessid' parameter of the 'print.php' script.
Description
SQL injection vulnerability in print.php in SaphpLesson 2.0 allows remote attackers to execute arbitrary SQL commands via the lessid parameter.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in SaphpLesson by injecting a UNION-based query to extract sensitive data (ModName and ModPassword) from the 'modretor' table. The attack leverages unsanitized input in the 'lessid' parameter of the 'print.php' script.