Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-2824. PoCs published by BlackHawk.
AI-analyzed exploit summary This exploit leverages a SQL injection vulnerability in AlstraSoft E-Friends <= 4.21 to retrieve an admin session ID by injecting a UNION-based query into the 'pack' parameter. It then uses the retrieved session ID to authenticate as an admin.
Description
SQL injection vulnerability in paypal.php in AlstraSoft E-Friends 4.21 and earlier allows remote attackers to execute arbitrary SQL commands via the pack parameter in a paypal action for index.php.
Exploits (1)
This exploit leverages a SQL injection vulnerability in AlstraSoft E-Friends <= 4.21 to retrieve an admin session ID by injecting a UNION-based query into the 'pack' parameter. It then uses the retrieved session ID to authenticate as an admin.