Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-1296. PoCs published by ajann.
AI-analyzed exploit summary This HTML-based exploit demonstrates a blind SQL injection vulnerability in AJ Classifieds 1.0 via the 'postingdetails.php' script. It crafts a malicious URL to extract MySQL user passwords by injecting a UNION-based SQL query.
Description
SQL injection vulnerability in postingdetails.php in AJ Classifieds 1.0 allows remote attackers to execute arbitrary SQL commands via the postingid parameter.
Exploits (1)
This HTML-based exploit demonstrates a blind SQL injection vulnerability in AJ Classifieds 1.0 via the 'postingdetails.php' script. It crafts a malicious URL to extract MySQL user passwords by injecting a UNION-based SQL query.