CVE-2006-1613
aWebNews 1.0 - SQL Injection via user123 Parameter or cid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-1613. PoCs published by Aliaksandr Hartsuyeu.
AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in aWebBB by injecting a UNION-based SQL query via the 'cid' parameter in visview.php. It bypasses input sanitization to extract arbitrary data from the database.
Description
Multiple SQL injection vulnerabilities in aWebNews 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) user123 variable in (a) login.php or (b) fpass.php; or (2) cid parameter to (c) visview.php.
Exploits (1)
The exploit demonstrates a SQL injection vulnerability in aWebBB by injecting a UNION-based SQL query via the 'cid' parameter in visview.php. It bypasses input sanitization to extract arbitrary data from the database.