CVE-2007-0129
LocazoList Classifieds < 2.01a_beta5 - SQL Injection via main.asp subcatID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0129. PoCs published by ajann.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in LocazoList <= v2.01a beta5 via the 'subcatID' parameter. It allows an attacker to extract sensitive information such as usernames and passwords from the 'admin' table.
Description
SQL injection vulnerability in main.asp in LocazoList 2.01a beta5 and earlier allows remote attackers to execute arbitrary SQL commands via the subcatID parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in LocazoList <= v2.01a beta5 via the 'subcatID' parameter. It allows an attacker to extract sensitive information such as usernames and passwords from the 'admin' table.