Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-1022. PoCs published by chernobiLe.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Turuncu Portal 1.0 by injecting a UNION-based query to extract user credentials (email, username, password) from the 'uyeler' table. The attack leverages insufficient input sanitization in the 'id' parameter of 'h_goster.asp'.
Description
SQL injection vulnerability in h_goster.asp in Turuncu Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in Turuncu Portal 1.0 by injecting a UNION-based query to extract user credentials (email, username, password) from the 'uyeler' table. The attack leverages insufficient input sanitization in the 'id' parameter of 'h_goster.asp'.