CVE-2006-6039
php_matchmaker < 4.06 - SQL Injection via matchdetail.php edit Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6039. PoCs published by SHiKaA.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Powie's PHP MatchMaker <= v4.05. The exploit leverages a UNION-based SQL injection in the 'edit' parameter of matchdetail.php to extract user credentials (username and password) from the database.
Description
SQL injection vulnerability in matchdetail.php in Powie's PHP MatchMaker 4.05 and earlier allows remote attackers to execute arbitrary SQL commands via the edit parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Powie's PHP MatchMaker <= v4.05. The exploit leverages a UNION-based SQL injection in the 'edit' parameter of matchdetail.php to extract user credentials (username and password) from the database.