CVE-2007-3290
LiveCMS <= 3.4 - SQL Injection via Categoria.php cid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3290. PoCs published by g00ns.
AI-analyzed exploit summary This Perl script exploits a SQL injection vulnerability in LiveCMS <= 3.4 via the 'cid' parameter in categoria.php. It retrieves admin credentials (username and password hash) and attempts to crack the hash using an external service.
Description
categoria.php in LiveCMS 3.4 and earlier allows remote attackers to obtain sensitive information via a ' (quote) character in the cid parameter, which reveals the path in a forced SQL error message.
Exploits (1)
This Perl script exploits a SQL injection vulnerability in LiveCMS <= 3.4 via the 'cid' parameter in categoria.php. It retrieves admin credentials (username and password hash) and attempts to crack the hash using an external service.