CVE-2007-3354
NetClassifieds Premium Edition - SQL Injection via s_user_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3354. PoCs published by laurent gaffie.
AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in NetClassifieds by injecting malicious SQL queries into the 'CatID' and 's_user_id' parameters. These queries extract sensitive data such as user emails and passwords from the database.
Description
Multiple SQL injection vulnerabilities in NetClassifieds Premium Edition allow remote attackers to execute arbitrary SQL commands via the s_user_id parameter to ViewCat.php and other unspecified vectors. NOTE: the CatID/ViewCat.php, CatID/gallery.php, and ItemNum/ViewItem.php vectors are already covered by CVE-2005-3978.
Exploits (1)
The exploit demonstrates SQL injection vulnerabilities in NetClassifieds by injecting malicious SQL queries into the 'CatID' and 's_user_id' parameters. These queries extract sensitive data such as user emails and passwords from the database.