CVE-2006-2459
PHP-Fusion <= 6.00.307 - Authenticated SQL Injection via srch_where Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2459. PoCs published by rgod.
AI-analyzed exploit summary This exploit leverages a SQL injection vulnerability in PHP-Fusion <= v6.00.306 to disclose admin credentials by injecting malicious SQL queries into the 'srch_where' parameter. It requires valid user credentials to authenticate and extract the admin username and password hash.
Description
SQL injection vulnerability in messages.php in PHP-Fusion 6.00.307 and earlier allows remote authenticated users to execute arbitrary SQL commands via the srch_where parameter.
Exploits (1)
This exploit leverages a SQL injection vulnerability in PHP-Fusion <= v6.00.306 to disclose admin credentials by injecting malicious SQL queries into the 'srch_where' parameter. It requires valid user credentials to authenticate and extract the admin username and password hash.