CVE-2007-5131
Interspire ActiveKB NX 2.x - SQL Injection via catId Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5131. PoCs published by Luna-Tic/XTErner.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in ActiveKB Knowledgebase Software via the 'catId' parameter in index.php. It allows an attacker to extract sensitive information such as user emails, passwords, and user IDs from the database.
Description
SQL injection vulnerability in index.php in Interspire ActiveKB NX 2.x allows remote attackers to execute arbitrary SQL commands via the catId parameter in a browse action. NOTE: it was separately reported that ActiveKB 1.5 is also affected.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in ActiveKB Knowledgebase Software via the 'catId' parameter in index.php. It allows an attacker to extract sensitive information such as user emails, passwords, and user IDs from the database.