CVE-2006-4867
gnuturk_portal_system < 2g - SQL Injection via t_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4867. PoCs published by p2y.
AI-analyzed exploit summary This exploit leverages a blind SQL injection vulnerability in Gnu Turk to extract admin credentials directly from the database. It constructs a malicious SQL query via URL manipulation to retrieve the username and password from the 'gtp_admins' table.
Description
SQL injection vulnerability in mods.php in GNUTurk 2G and earlier allows remote attackers to execute arbitrary SQL commands via the t_id parameter when the go parameter is "Forum."
Exploits (1)
This exploit leverages a blind SQL injection vulnerability in Gnu Turk to extract admin credentials directly from the database. It constructs a malicious SQL query via URL manipulation to retrieve the username and password from the 'gtp_admins' table.