CVE-2007-2537
NPDS < 5.10 - Authenticated SQL Injection via Cookie or X-Forwarded-For Header
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2537. PoCs published by Gu1ll4um3r0m41n.
AI-analyzed exploit summary This exploit targets NPDS <= 5.10, leveraging SQL injection via manipulated cookies and HTTP headers to extract admin credentials and achieve remote code execution by injecting PHP code into configuration files.
Description
Multiple SQL injection vulnerabilities in mainfile.php in NPDS 5.10 and earlier allow remote authenticated users to execute arbitrary SQL commands via a (1) nickname or (2) Id in a cookie, or (3) the X-Forwarded-For (X_FORWARDED_FOR) HTTP header.
Exploits (1)
This exploit targets NPDS <= 5.10, leveraging SQL injection via manipulated cookies and HTTP headers to extract admin credentials and achieve remote code execution by injecting PHP code into configuration files.