CVE-2007-3520
Easybe 1-2-3 Music Store - SQL Injection via CategoryID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3520. PoCs published by t0pP8uZz.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Easybe 1-2-3 Music Store's process.php, allowing an attacker to retrieve admin credentials via a UNION-based SQLi in the CategoryID parameter. The payload extracts login and password data from the 'user' table and displays it in an error message.
Description
SQL injection vulnerability in process.php in Easybe 1-2-3 Music Store allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Easybe 1-2-3 Music Store's process.php, allowing an attacker to retrieve admin credentials via a UNION-based SQLi in the CategoryID parameter. The payload extracts login and password data from the 'user' table and displays it in an error message.