CVE-2007-0053
ASP SiteWare autoDealer < 2.0 - SQL Injection via detail.asp iPro Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2007-0053. PoCs published by Sid3^effects, ajann.
AI-analyzed exploit summary This is a writeup describing SQL injection vulnerabilities in AutoDealer software. It provides URLs for exploitation but does not include functional exploit code.
Description
SQL injection vulnerability in detail.asp in ASP SiteWare autoDealer 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the iPro parameter.
Exploits (2)
This is a writeup describing SQL injection vulnerabilities in AutoDealer software. It provides URLs for exploitation but does not include functional exploit code.
This exploit demonstrates a SQL injection vulnerability in autoDealer <= 2.0 (iPro) via the 'iPro' parameter in detail.asp. It allows an attacker to extract sensitive information such as user access levels and passwords from the database.