CVE-2007-2959
cpCommerce - SQL Injection via manufacturer.php id_manufacturer Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2959. PoCs published by laurent gaffie.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in cpCommerce 1.1.0 by injecting a UNION-based query to extract sensitive data, including passwords and system files. The PoC leverages the LOAD_FILE function to read arbitrary files from the server.
Description
SQL injection vulnerability in manufacturer.php in cpCommerce before 1.1.0 allows remote attackers to execute arbitrary SQL commands via the id_manufacturer parameter.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in cpCommerce 1.1.0 by injecting a UNION-based query to extract sensitive data, including passwords and system files. The PoC leverages the LOAD_FILE function to read arbitrary files from the server.