Exploitation Summary
EIP tracks 2 public exploits for CVE-2006-3142. PoCs published by Cold Zero, CrAsh_oVeR_rIdE.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in vbzoom 1.x via the MainID parameter in forum.php. It allows an attacker to extract user information, including passwords, from the Member table.
Description
SQL injection vulnerability in forum.php in VBZooM 1.11 allows remote attackers to execute arbitrary SQL commands via the MainID parameter.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in vbzoom 1.x via the MainID parameter in forum.php. It allows an attacker to extract user information, including passwords, from the Member table.
This exploit demonstrates SQL injection in VBZooM by injecting malicious SQL queries via the MainID parameter to extract user information or passwords from the Member table. The PoC provides direct URLs to exploit the vulnerability.