CVE-2007-3549
Buddy Zone 1.5 - SQL Injection via view_sub_cat.php cat_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-3549. PoCs published by t0pP8uZz.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Buddy Zone 1.5 via the 'cat_id' parameter in 'view_sub_cat.php'. It allows an attacker to extract admin and user credentials by manipulating the SQL query through UNION-based injection.
Description
SQL injection vulnerability in view_sub_cat.php in Buddy Zone 1.5 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Buddy Zone 1.5 via the 'cat_id' parameter in 'view_sub_cat.php'. It allows an attacker to extract admin and user credentials by manipulating the SQL query through UNION-based injection.