Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-2674. PoCs published by Mehmet Ince.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Pre Shopping Mall v1.0 via the 'prodid' parameter in detail.php, allowing unauthorized access to the admin password. The payload uses a UNION-based SQLi to extract data from the admin table.
Description
SQL injection vulnerability in detail.php in Pre Shopping Mall 1.0 allows remote attackers to execute arbitrary SQL commands via the prodid parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Pre Shopping Mall v1.0 via the 'prodid' parameter in detail.php, allowing unauthorized access to the admin password. The payload uses a UNION-based SQLi to extract data from the admin table.