Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-3682. PoCs published by CypherXero.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in OpenLD <= 1.2.2, allowing an attacker to extract admin credentials (username and MD5 hash) via a UNION-based SQLi attack. The payload is injected through the 'id' parameter in the URL.
Description
SQL injection vulnerability in index.php in OpenLD 1.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in OpenLD <= 1.2.2, allowing an attacker to extract admin credentials (username and MD5 hash) via a UNION-based SQLi attack. The payload is injected through the 'id' parameter in the URL.