Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-0970. PoCs published by Moran Zavdi.
AI-analyzed exploit summary The provided text describes a vulnerability in WebTester (CVE-2007-0970) involving SQL injection and XSS due to improper input sanitization. It includes a sample URL demonstrating the SQL injection but lacks executable exploit code.
Description
Multiple SQL injection vulnerabilities in WebTester 5.0.20060927 and earlier allow remote attackers to execute arbitrary SQL commands via the testID parameter to directions.php, and unspecified parameters to other files that accept GET or POST input.
Exploits (1)
The provided text describes a vulnerability in WebTester (CVE-2007-0970) involving SQL injection and XSS due to improper input sanitization. It includes a sample URL demonstrating the SQL injection but lacks executable exploit code.