CVE-2007-5261
MultiCart 1.0 - SQL Injection via catid or ddlCategory Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5261. PoCs published by k1tk4t.
AI-analyzed exploit summary This Perl script exploits a blind SQL injection vulnerability in MultiCart 1.0 via the 'ddlCategory' parameter in search.php. It extracts admin credentials by brute-forcing character-by-character using SUBSTRING and CHAR functions.
Description
Multiple SQL injection vulnerabilities in MultiCart 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) catid parameter to categorydetail.php and the (2) ddlCategory parameter to search.php.
Exploits (1)
This Perl script exploits a blind SQL injection vulnerability in MultiCart 1.0 via the 'ddlCategory' parameter in search.php. It extracts admin credentials by brute-forcing character-by-character using SUBSTRING and CHAR functions.