Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-1171. PoCs published by DarkFig.
AI-analyzed exploit summary This exploit targets a blind SQL injection vulnerability in NukeSentinel 2.5.05 via the 'nsbypass.php' file. It extracts user password hashes by manipulating the 'tid' parameter and injecting SQL payloads through the 'admin' cookie.
Description
SQL injection vulnerability in includes/nsbypass.php in NukeSentinel 2.5.05, 2.5.11, and other versions before 2.5.12 allows remote attackers to execute arbitrary SQL commands via an admin cookie.
Exploits (1)
This exploit targets a blind SQL injection vulnerability in NukeSentinel 2.5.05 via the 'nsbypass.php' file. It extracts user password hashes by manipulating the 'tid' parameter and injecting SQL payloads through the 'admin' cookie.