Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-4054. PoCs published by t0pP8uZz.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in PHP123 Top Sites, allowing an attacker to extract admin and user credentials via crafted UNION-based SQL queries. The PoC provides direct URLs to retrieve username and password hashes from the database.
Description
SQL injection vulnerability in category.php in PHP123 Top Sites allows remote attackers to execute arbitrary SQL commands via the cat parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in PHP123 Top Sites, allowing an attacker to extract admin and user credentials via crafted UNION-based SQL queries. The PoC provides direct URLs to retrieve username and password hashes from the database.