CVE-2007-1960
Rha7 Downloads Module for XOOPS - SQL Injection via visit.php lid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-1960. PoCs published by ajann.
AI-analyzed exploit summary This Perl script exploits a blind SQL injection vulnerability in XOOPS Module Rha7 Downloads 1.0 via the 'visit.php' file. It extracts admin credentials (username and password) from the 'xoops_users' table by manipulating the 'cid' and 'lid' parameters.
Description
SQL injection vulnerability in visit.php in the Rha7 Downloads (rha7downloads) 1.0 module for XOOPS, and possibly other versions up to 1.10, allows remote attackers to execute arbitrary SQL commands via the lid parameter.
Exploits (1)
This Perl script exploits a blind SQL injection vulnerability in XOOPS Module Rha7 Downloads 1.0 via the 'visit.php' file. It extracts admin credentials (username and password) from the 'xoops_users' table by manipulating the 'cid' and 'lid' parameters.