CVE-2007-4645
NMDeluxe 2.0.0 - SQL Injection via id Parameter in newspost Action
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-4645. PoCs published by not sec group.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in NMDeluxe 2.0.0, allowing an attacker to extract user credentials via a UNION-based attack. The vulnerable parameter is 'id' in the 'newspost' action.
Description
SQL injection vulnerability in index.php in NMDeluxe 2.0.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a newspost do action, a different vulnerability than CVE-2006-1108.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in NMDeluxe 2.0.0, allowing an attacker to extract user credentials via a UNION-based attack. The vulnerable parameter is 'id' in the 'newspost' action.