Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-5054. PoCs published by Fix TR.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in iyzi Forum s1 b2 (tr) via the 'uye_nu' parameter in 'uye_ayrinti.asp'. It extracts usernames and SHA-256 hashed passwords from the 'iyzi_uyeler' table by exploiting improper input sanitization.
Description
SQL injection vulnerability in uye/uye_ayrinti.asp in iyzi Forum 1 Beta 2 and earlier allows remote attackers to execute arbitrary SQL commands via the uye_nu parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in iyzi Forum s1 b2 (tr) via the 'uye_nu' parameter in 'uye_ayrinti.asp'. It extracts usernames and SHA-256 hashed passwords from the 'iyzi_uyeler' table by exploiting improper input sanitization.