Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-4863. PoCs published by netVigilance.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Saxon 5.4 by injecting a UNION-based query to extract user credentials from the SX_saxon_users table. The attack leverages unsanitized input in the 'template' parameter to manipulate the SQL query.
Description
SQL injection vulnerability in example.php in SAXON 5.4 allows remote attackers to execute arbitrary SQL commands via the template parameter.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in Saxon 5.4 by injecting a UNION-based query to extract user credentials from the SX_saxon_users table. The attack leverages unsanitized input in the 'template' parameter to manipulate the SQL query.