Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-1837. PoCs published by snatcher.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Fuju News 1.0, allowing an attacker to bypass authentication and extract admin credentials via a crafted UNION-based SQL query. It also highlights an authentication bypass by setting a cookie named 'authorized' to '1'.
Description
SQL injection vulnerability in archiv2.php in Fuju News 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Fuju News 1.0, allowing an attacker to bypass authentication and extract admin credentials via a crafted UNION-based SQL query. It also highlights an authentication bypass by setting a cookie named 'authorized' to '1'.