Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-3449. PoCs published by Crackers_Child.
AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in 6ALBlog, allowing an attacker to extract user credentials (username and password) via a crafted SQL query. It also includes a remote file inclusion (RFI) exploit path for post-authentication exploitation.
Description
SQL injection vulnerability in member.php in 6ALBlog allows remote attackers to execute arbitrary SQL commands via the newsid parameter.
Exploits (1)
The exploit demonstrates a SQL injection vulnerability in 6ALBlog, allowing an attacker to extract user credentials (username and password) via a crafted SQL query. It also includes a remote file inclusion (RFI) exploit path for post-authentication exploitation.