Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-0847. PoCs published by GregStar.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in OTSCMS 2.1.5. The SQLi allows unauthorized data extraction via a crafted 'id' parameter, while the XSS executes arbitrary JavaScript through the 'name' parameter.
Description
SQL injection vulnerability in mod/PM/reply.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to priv.php.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in OTSCMS 2.1.5. The SQLi allows unauthorized data extraction via a crafted 'id' parameter, while the XSS executes arbitrary JavaScript through the 'name' parameter.