CVE-2007-2006
pl-php < 0.9_beta - SQL Injection via Login or Pass Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2006. PoCs published by Omni.
AI-analyzed exploit summary This is a technical writeup detailing multiple vulnerabilities in pL-PHP beta 0.9, including SQL injection, admin access bypass via global variable manipulation, and local file inclusion. It includes code snippets and proof-of-concept examples.
Description
Multiple SQL injection vulnerabilities in login.php in pL-PHP beta 0.9 allow remote attackers to execute arbitrary SQL commands via the (1) login or (2) pass parameter.
Exploits (1)
This is a technical writeup detailing multiple vulnerabilities in pL-PHP beta 0.9, including SQL injection, admin access bypass via global variable manipulation, and local file inclusion. It includes code snippets and proof-of-concept examples.