CVE-2006-4585
Tr Forum 2.0 - Authenticated SQL Injection via id2 Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4585. PoCs published by DarkFig.
AI-analyzed exploit summary This exploit demonstrates SQL injection and authentication bypass in Tr Forum V2.0 by creating a new admin user and extracting admin credentials via a UNION-based SQLi attack.
Description
SQL injection vulnerability in admin/editer.php in Tr Forum 2.0 allows remote authenticated users to execute arbitrary SQL commands via the id2 parameter. NOTE: this can be leveraged with other Tr Forum vulnerabilities to allow unauthenticated attackers to gain privileges.
Exploits (1)
This exploit demonstrates SQL injection and authentication bypass in Tr Forum V2.0 by creating a new admin user and extracting admin credentials via a UNION-based SQLi attack.