Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-3810. PoCs published by t0pP8uZz.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Realtor 747, allowing an attacker to extract the admin password from the database via a crafted UNION-based SQL query. The password is retrieved from the AD747_CONFIG table where config_key is 'password'.
Description
SQL injection vulnerability in index.php in Realtor 747 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Realtor 747, allowing an attacker to extract the admin password from the database via a crafted UNION-based SQL query. The password is retrieved from the AD747_CONFIG table where config_key is 'password'.