Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-4056. PoCs published by t0pP8uZz.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Adult Directory software, allowing an attacker to extract admin credentials via a crafted UNION-based SQL query. The payload retrieves username and password from the admin table.
Description
SQL injection vulnerability in directory.php in Prozilla Adult Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action. NOTE: the original report indicated that this was the "photo" SourceForge project (aka Maan Bsat Photo Collection), but that was incorrect.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Adult Directory software, allowing an attacker to extract admin credentials via a crafted UNION-based SQL query. The payload retrieves username and password from the admin table.