CVE-2006-3572
papoo < 3.0.0_rc3 - SQL Injection via forumthread.php msgid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-3572. PoCs published by rgod.
AI-analyzed exploit summary This PHP script exploits a SQL injection vulnerability in Papoo CMS <= 3_RC3 to disclose admin credentials. It automates the disclosure of the table prefix and performs a UNION-based SQL injection to extract usernames and MD5 password hashes from the database.
Description
SQL injection vulnerability in forumthread.php in Papoo 3 RC3 and earlier allows remote attackers to execute arbitrary SQL commands via the msgid parameter.
Exploits (1)
This PHP script exploits a SQL injection vulnerability in Papoo CMS <= 3_RC3 to disclose admin credentials. It automates the disclosure of the table prefix and performs a UNION-based SQL injection to extract usernames and MD5 password hashes from the database.