CVE-2007-1838
Xoops Friendfinder Module < 3.3 - SQL Injection via id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-1838. PoCs published by ajann.
AI-analyzed exploit summary This Perl script exploits a blind SQL injection vulnerability in Xoops Module Friendfinder <= 3.3 via the 'id' parameter in view.php. It extracts admin credentials (username and password) from the xoops_users table by crafting a malicious SQL query.
Description
SQL injection vulnerability in view.php in the Friendfinder 3.3 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
This Perl script exploits a blind SQL injection vulnerability in Xoops Module Friendfinder <= 3.3 via the 'id' parameter in view.php. It extracts admin credentials (username and password) from the xoops_users table by crafting a malicious SQL query.