Exploitation Summary
EIP tracks 1 public exploit for CVE-2006-6070. PoCs published by ajann.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in ASPNuke <= 0.80 via the 'StateCode' parameter in the registration module. The PoC includes a crafted URL that updates a poll question to 'hacked' as proof of exploitation.
Description
SQL injection vulnerability in module/account/register/register.asp in ASP Nuke 0.80 and earlier allows remote attackers to execute arbitrary SQL commands via the StateCode parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in ASPNuke <= 0.80 via the 'StateCode' parameter in the registration module. The PoC includes a crafted URL that updates a poll question to 'hacked' as proof of exploitation.