CVE-2007-5630
BBPortalS 1.5.10-2.0 - SQL Injection via tnews.php id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5630. PoCs published by Max007.
AI-analyzed exploit summary This Perl script exploits a blind SQL injection vulnerability in BBPortalS/BBsProcesS via the 'tnews.php' script. It automates the discovery of the number of fields and extracts admin credentials from the 'users' table.
Description
SQL injection vulnerability in tnews.php in BBsProcesS BBPortalS 1.5.10 through 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a tnews action.
Exploits (1)
This Perl script exploits a blind SQL injection vulnerability in BBPortalS/BBsProcesS via the 'tnews.php' script. It automates the discovery of the number of fields and extracts admin credentials from the 'users' table.