CVE-2007-1026
xlatunes < 0.1 - SQL Injection via view.php album Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-1026. PoCs published by Bl0od3r.
AI-analyzed exploit summary This is a writeup describing a SQL injection vulnerability in an unspecified web application. It provides a URL with a malicious SQL query to exploit a UNION-based SQLi in the 'album' parameter.
Description
SQL injection vulnerability in view.php in XLAtunes 0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the album parameter in view mode. NOTE: some of these details are obtained from third party information.
Exploits (1)
This is a writeup describing a SQL injection vulnerability in an unspecified web application. It provides a URL with a malicious SQL query to exploit a UNION-based SQLi in the 'album' parameter.