Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-2299. PoCs published by Kacper.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Frogss CMS <= 0.7, allowing an attacker to extract admin credentials via three different injection points in the application.
Description
Multiple SQL injection vulnerabilities in Frogss CMS 0.7 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) dzial parameter to (a) katalog.php, or the (2) t parameter to (b) forum.php or (c) forum/viewtopic.php, different vectors than CVE-2006-4536.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in Frogss CMS <= 0.7, allowing an attacker to extract admin credentials via three different injection points in the application.