Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-2541. PoCs published by FarhadKey.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Zix Forum <= 1.12 via the 'layid' parameter in 'settings.asp' and 'main.asp'. The PoC extracts administrator credentials in clear text by manipulating SQL queries through a UNION-based attack.
Description
SQL injection vulnerability in settings.asp in Zixforum 1.12 allows remote attackers to execute arbitrary SQL commands via the layid parameter to (1) login.asp and (2) main.asp.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Zix Forum <= 1.12 via the 'layid' parameter in 'settings.asp' and 'main.asp'. The PoC extracts administrator credentials in clear text by manipulating SQL queries through a UNION-based attack.