CVE-2006-2339
evoTopsites 2.x and evoTopsites Pro 2.x - SQL Injection via cat_id or id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2339. PoCs published by Hamid Ebadi.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in evoTopsite by injecting a UNION-based query to extract user passwords from the database. The attack leverages unsanitized input in the 'cat_id' parameter to manipulate the SQL query.
Description
SQL injection vulnerability in index.php in evoTopsites 2.x and evoTopsites Pro 2.x allows remote attackers to execute arbitrary SQL commands via the (1) cat_id and (2) id parameters.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in evoTopsite by injecting a UNION-based query to extract user passwords from the database. The attack leverages unsanitized input in the 'cat_id' parameter to manipulate the SQL query.