CVE-2007-0128
Digirez < 3.4 - SQL Injection via info_book.asp book_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0128. PoCs published by ajann.
AI-analyzed exploit summary This Perl script exploits a blind SQL injection vulnerability in DigiRez <= V3.4 via the 'book_id' parameter in 'info_book.asp'. It extracts admin credentials (username and password) from the 'members' table by crafting a malicious SQL query.
Description
SQL injection vulnerability in info_book.asp in Digirez 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the book_id parameter.
Exploits (1)
This Perl script exploits a blind SQL injection vulnerability in DigiRez <= V3.4 via the 'book_id' parameter in 'info_book.asp'. It extracts admin credentials (username and password) from the 'members' table by crafting a malicious SQL query.