Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-3814. PoCs published by Coloss.
AI-analyzed exploit summary This is a SQL injection exploit for MkPortal <= 1.1.1 targeting the 'reviews' and 'gallery' modules. It supports multiple forum types (phpbb, smf, mybb) and uses both direct and blind SQL injection techniques to extract data.
Description
Multiple SQL injection vulnerabilities in MKPortal 1.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the idurlo field in the delete_urlo function in (a) index.php in the urlobox module; the iden field in the (2) update_file and (3) del_file functions in (b) index.php in the reviews module; the (4) idnews field in the delete_news function and the (5) idcomm field in the del_comment function in (c) index.php in the news module; the (6) idcomm field in the delete_comments function in (d) index.php in the gallery module; the iden field in the (7) edit_file, (8) update_file, and (9) del_file functions in index.php in the gallery module; the (10) ide and (11) cat fields in the slide_update function in index.php in the gallery module; the iden field in the (12) update_file and (13) del_file functions in (d) index.php in the downloads module; and other unspecified vectors.
Exploits (1)
This is a SQL injection exploit for MkPortal <= 1.1.1 targeting the 'reviews' and 'gallery' modules. It supports multiple forum types (phpbb, smf, mybb) and uses both direct and blind SQL injection techniques to extract data.