CVE-2006-6813
mxmania_file_upload_manager < 1.0.6 - SQL Injection via ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-6813. PoCs published by ajann.
AI-analyzed exploit summary This exploit targets a SQL injection vulnerability in File Upload Manager <= 1.0.6 via the 'detail.asp' page. It extracts admin credentials by injecting a UNION-based SQL query to retrieve username and password from the 'tbl_members' table.
Description
SQL injection vulnerability in detail.asp in Mxmania File Upload Manager (FUM) 1.0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.
Exploits (1)
This exploit targets a SQL injection vulnerability in File Upload Manager <= 1.0.6 via the 'detail.asp' page. It extracts admin credentials by injecting a UNION-based SQL query to retrieve username and password from the 'tbl_members' table.