Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-2685. PoCs published by Jesper Jurcenoks.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Jetbox 2.1. The first URL extracts user credentials via UNION-based SQLi, while the second URL abuses the vulnerability to send spam emails by manipulating the `login` parameter.
Description
Multiple SQL injection vulnerabilities in index.php in Jetbox CMS 2.1 allow remote attackers to execute arbitrary SQL commands via the (1) view or (2) login parameter.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in Jetbox 2.1. The first URL extracts user credentials via UNION-based SQLi, while the second URL abuses the vulnerability to send spam emails by manipulating the `login` parameter.