CVE-2006-1853
ModernBill < 4.3.2 - SQL Injection via User ID or Admin Where/Order Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-1853. PoCs published by r0t.
AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in ModernBill, detailing vulnerable parameters in specific URLs. It does not include executable exploit code but outlines attack vectors.
Description
Multiple SQL injection vulnerabilities in ModernBill 4.3.2 and earlier allow remote attackers or administrators to execute arbitrary SQL commands via the (1) id parameter in (a) user.php, or (2) where and (3) order parameters to (b) admin.php.
Exploits (1)
The provided text describes an SQL injection vulnerability in ModernBill, detailing vulnerable parameters in specific URLs. It does not include executable exploit code but outlines attack vectors.