CVE-2007-0196
motionborg_web_real_estate < 2.1 - SQL Injection via txtUserName Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0196. PoCs published by ajann.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in MOTIONBORG Web Real Estate <= v2.1 via the admin_check_user.asp endpoint. It allows an attacker to manipulate the database to reset credentials and gain unauthorized access.
Description
SQL injection vulnerability in admin_check_user.asp in Motionborg Web Real Estate 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (txtUserName parameter) and possibly other parameters. NOTE: some details were obtained from third party information.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in MOTIONBORG Web Real Estate <= v2.1 via the admin_check_user.asp endpoint. It allows an attacker to manipulate the database to reset credentials and gain unauthorized access.