CVE-2007-0502
webSPELL 4.01.02 - SQL Injection via gallery.php picID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-0502. PoCs published by r00t.
AI-analyzed exploit summary This exploit targets a SQL injection vulnerability in webSPELL's gallery.php, allowing an attacker to extract user password hashes by brute-forcing each character of the hash. It uses a custom HTTP client class to automate requests and parse responses.
Description
SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote attackers to execute arbitrary SQL commands via the picID parameter, a different vector than CVE-2007-0492.
Exploits (1)
This exploit targets a SQL injection vulnerability in webSPELL's gallery.php, allowing an attacker to extract user password hashes by brute-forcing each character of the hash. It uses a custom HTTP client class to automate requests and parse responses.