CVE-2007-1566

NetVIOS Portal - SQL Injection via NewsID Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2007-1566. PoCs published by parad0x, ajann.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in NetVios Portal's page.asp. The PoC provides a URL with a crafted NewsID parameter to extract user credentials from the database.

Description

SQL injection vulnerability in News/page.asp in NetVIOS Portal allows remote attackers to execute arbitrary SQL commands via the NewsID parameter. NOTE: this issue might be the same as CVE-2006-5954.

Exploits (2)

exploitdb WORKING POC VERIFIED
by parad0x · textwebappsasp
https://www.exploit-db.com/exploits/3520

This exploit demonstrates a SQL injection vulnerability in NetVios Portal's page.asp. The PoC provides a URL with a crafted NewsID parameter to extract user credentials from the database.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: NetVios Portal
No auth needed
Prerequisites: Target running NetVios Portal with vulnerable page.asp endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by ajann · textwebappsasp
https://www.exploit-db.com/exploits/2780

This exploit demonstrates a SQL injection vulnerability in NetVios News Application via the 'NewsID' parameter in page.asp. It allows an attacker to extract sensitive information such as usernames and passwords from the database.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: NetVios <= 2.0 [News Application]
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/33072
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/23045
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/3520

Scores

EPSS 0.0218
EPSS Percentile 80.0%

Details

Status published
Products (1)
netvios/netvios
Published Mar 21, 2007
Tracked Since Feb 18, 2026