CVE-2007-4171
auracms modul_forum_sederhana - SQL Injection via komentar.php id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-4171. PoCs published by k1tk4t.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in AuraCMS's Forum Module, allowing an attacker to extract user credentials via a crafted URL. The vulnerability stems from improper filtering of the 'id' parameter in the 'komentar.php' file.
Description
SQL injection vulnerability in komentar.php in the Forum Module for auraCMS (Modul Forum Sederhana) allows remote attackers to execute arbitrary SQL commands via the id parameter to the default URI. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in AuraCMS's Forum Module, allowing an attacker to extract user credentials via a crafted URL. The vulnerability stems from improper filtering of the 'id' parameter in the 'komentar.php' file.