CVE-2006-4478
Visual Shapers ezContents 2.0.3 - SQL Injection via Groupname Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4478. PoCs published by DarkFig.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in ezContents, allowing an attacker to extract user passwords from the database and write them to a file on the server. The attack leverages a UNION-based SQL injection to exfiltrate data via the INTO OUTFILE clause.
Description
SQL injection vulnerability in headeruserdata.php in Visual Shapers ezContents 2.0.3 allows remote attackers to execute arbitrary SQL commands via the groupname parameter.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in ezContents, allowing an attacker to extract user passwords from the database and write them to a file on the server. The attack leverages a UNION-based SQL injection to exfiltrate data via the INTO OUTFILE clause.