CVE-2007-4258

Prozilla Pub Site Directory - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-4258. PoCs published by t0pP8uZz.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Prozilla Pub Site Directory, allowing an attacker to extract admin and user credentials via UNION-based SQLi. The PoC provides direct URLs to leak username and password hashes from the 'admin' and 'users' tables.

Description

SQL injection vulnerability in directory.php in Prozilla Pub Site Directory allows remote attackers to execute arbitrary SQL commands via the cat parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by t0pP8uZz · textwebappsphp
https://www.exploit-db.com/exploits/4265

This exploit demonstrates a SQL injection vulnerability in Prozilla Pub Site Directory, allowing an attacker to extract admin and user credentials via UNION-based SQLi. The PoC provides direct URLs to leak username and password hashes from the 'admin' and 'users' tables.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Prozilla Pub Site Directory (version unspecified)
No auth needed
Prerequisites: Target application with vulnerable 'directory.php' endpoint · SQLi vulnerability in the 'cat' parameter
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/4265
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/25209

Scores

EPSS 0.0095
EPSS Percentile 56.6%

Details

CWE
CWE-89
Status published
Products (1)
prozilla/prozilla_pub_site_directory
Published Aug 08, 2007
Tracked Since Feb 18, 2026