CVE-2006-6038
pForum < 1.29a - SQL Injection via editpoll.php id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6038. PoCs published by SHiKaA.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Powie's PHP Forum v1.29a via the 'editpoll.php' script. It allows an attacker to extract user credentials (username and password) by manipulating the 'id' parameter.
Description
SQL injection vulnerability in editpoll.php in Powie's PHP Forum (pForum) 1.29a and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Powie's PHP Forum v1.29a via the 'editpoll.php' script. It allows an attacker to extract user credentials (username and password) by manipulating the 'id' parameter.