Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-1172. PoCs published by DarkFig.
AI-analyzed exploit summary This exploit leverages a SQL injection vulnerability in NukeSentinel 2.5.05 to perform file disclosure. It manipulates the 'Client-IP' header to inject malicious SQL queries, ultimately reading arbitrary files from the server.
Description
SQL injection vulnerability in nukesentinel.php in NukeSentinel 2.5.05, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, aka the "File Disclosure Exploit."
Exploits (1)
This exploit leverages a SQL injection vulnerability in NukeSentinel 2.5.05 to perform file disclosure. It manipulates the 'Client-IP' header to inject malicious SQL queries, ultimately reading arbitrary files from the server.