Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-5061. PoCs published by IHTeam.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Clansphere 2007.4 via the 'cat_id' parameter in the 'banners' module. It bypasses authentication by injecting a UNION-based query to extract user credentials from the database.
Description
SQL injection vulnerability in mods/banners/navlist.php in Clansphere 2007.4 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php in a banners action.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Clansphere 2007.4 via the 'cat_id' parameter in the 'banners' module. It bypasses authentication by injecting a UNION-based query to extract user credentials from the database.