Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-3301. PoCs published by Ivan Almuina.
AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in FuseTalk, where the 'errorcode' parameter in 'autherror.cfm' is not properly sanitized. It includes a sample exploit URL but lacks executable code.
Description
SQL injection vulnerability in forum/include/error/autherror.cfm in FuseTalk allows remote attackers to execute arbitrary SQL commands via the errorcode parameter. NOTE: a patch may have been released privately between April and June 2007. NOTE: this issue may overlap CVE-2007-3273.
Exploits (1)
The provided text describes an SQL injection vulnerability in FuseTalk, where the 'errorcode' parameter in 'autherror.cfm' is not properly sanitized. It includes a sample exploit URL but lacks executable code.