Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-3027. PoCs published by ajann.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Enthrallweb ePhotos 1.0 via the 'subLevel2.asp' script. The PoC provides a URL with a crafted 'SUB_ID' parameter to extract user credentials from the database.
Description
Multiple SQL injection vulnerabilities in Enthrallwebe ePhotos 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) CAT_ID parameter in (a) subphotos.asp and (b) subLevel2.asp, the (2) AL_ID parameter in (c) photo.asp, and the (3) SUB_ID parameter in (d) subLevel2.asp.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Enthrallweb ePhotos 1.0 via the 'subLevel2.asp' script. The PoC provides a URL with a crafted 'SUB_ID' parameter to extract user credentials from the database.