CVE-2007-3196
vBSupport Integrated Ticket System 3.x.x - SQL Injection via Ticket ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3196. PoCs published by rUnViRuS.
AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in vBSupport, where the 'ticketid' parameter in the 'showticket' action is not properly sanitized. This allows an attacker to manipulate SQL queries and perform unauthorized actions on the database.
Description
SQL injection vulnerability in vBSupport.php in vSupport Integrated Ticket System 3.x.x allows remote attackers to execute arbitrary SQL commands via the ticketid parameter in a showticket action.
Exploits (1)
The provided text describes an SQL injection vulnerability in vBSupport, where the 'ticketid' parameter in the 'showticket' action is not properly sanitized. This allows an attacker to manipulate SQL queries and perform unauthorized actions on the database.