CVE-2006-2697
Easy-Content Forums 1.0 - SQL Injection via startletter or forumname Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-2697. PoCs published by ajann.
AI-analyzed exploit summary The exploit demonstrates SQL injection and XSS vulnerabilities in Easy-Content Forums 1.0 by providing functional URLs with crafted input. It includes examples for extracting user passwords via SQLi and executing arbitrary JavaScript via XSS.
Description
Multiple SQL injection vulnerabilities in Easy-Content Forums 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) startletter parameter in userview.asp and the (2) forumname parameter in topics.asp.
Exploits (1)
The exploit demonstrates SQL injection and XSS vulnerabilities in Easy-Content Forums 1.0 by providing functional URLs with crafted input. It includes examples for extracting user passwords via SQLi and executing arbitrary JavaScript via XSS.