CVE-2006-3571
papoo < 3 RC3 - Cross-Site Scripting via Hilfe.php Titel or Ausgabe Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-3571. PoCs published by rgod.
AI-analyzed exploit summary This PHP script exploits a SQL injection vulnerability in Papoo CMS <= 3_RC3 to disclose admin credentials. It automates the disclosure of the table prefix and performs a UNION-based SQL injection to extract usernames and MD5 password hashes from the database.
Description
Multiple cross-site scripting (XSS) vulnerabilities in interna/hilfe.php in Papoo 3 RC3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) titel or (2) ausgabe parameters.
Exploits (1)
This PHP script exploits a SQL injection vulnerability in Papoo CMS <= 3_RC3 to disclose admin credentials. It automates the disclosure of the table prefix and performs a UNION-based SQL injection to extract usernames and MD5 password hashes from the database.