Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-2847. PoCs published by ajann.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in aspWebLinks 2.0, allowing an attacker to retrieve the administrative password via a crafted URL. It also includes an HTML form to change the admin password by submitting a POST request to the vulnerable endpoint.
Description
SQL injection vulnerability in links.asp in aspWebLinks 2.0 allows remote attackers to execute arbitrary SQL commands via the linkID parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in aspWebLinks 2.0, allowing an attacker to retrieve the administrative password via a crafted URL. It also includes an HTML form to change the admin password by submitting a POST request to the vulnerable endpoint.