CVE-2007-4952
OmniStar Article Manager - SQL Injection via Page ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-4952. PoCs published by Cold Zero.
AI-analyzed exploit summary This script is a proof-of-concept exploit for CVE-2007-4952, demonstrating SQL injection in Omnistar Article Manager Software. It constructs URLs to extract admin names and password hashes via union-based SQL injection.
Description
SQL injection vulnerability in article.php in OmniStar Article Manager allows remote attackers to execute arbitrary SQL commands via the page_id parameter in a favorite op action, a different vector than CVE-2006-5917.
Exploits (1)
This script is a proof-of-concept exploit for CVE-2007-4952, demonstrating SQL injection in Omnistar Article Manager Software. It constructs URLs to extract admin names and password hashes via union-based SQL injection.