CVE-2006-5881
Dynamic Dataworx NuCommunity 1.0 - SQL Injection via cl_cat_ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5881. PoCs published by ajann.
AI-analyzed exploit summary This Perl script exploits a SQL injection vulnerability in NuCommunity 1.0 via the 'cl_CatListing.asp' page. It extracts admin credentials by injecting a UNION-based SQL query to retrieve the username and password from the 'admin' table.
Description
SQL injection vulnerability in cl_CatListing.asp in Dynamic Dataworx NuCommunity 1.0 allows remote attackers to execute arbitrary SQL commands via the cl_cat_ID parameter.
Exploits (1)
This Perl script exploits a SQL injection vulnerability in NuCommunity 1.0 via the 'cl_CatListing.asp' page. It extracts admin credentials by injecting a UNION-based SQL query to retrieve the username and password from the 'admin' table.