CVE-2006-5886
Dynamic Dataworx NuRealestate 1.0 - SQL Injection via PropID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-5886. PoCs published by ajann.
AI-analyzed exploit summary This Perl script exploits a SQL injection vulnerability in NuRems 1.0 via the 'propertysdetails.asp' page. It crafts a malicious SQL query to extract admin credentials (username, password, email) from the 'agents' table.
Description
SQL injection vulnerability in propertysdetails.asp in Dynamic Dataworx NuRealestate (NuRems) 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the PropID parameter.
Exploits (1)
This Perl script exploits a SQL injection vulnerability in NuRems 1.0 via the 'propertysdetails.asp' page. It crafts a malicious SQL query to extract admin credentials (username, password, email) from the 'agents' table.