CVE-2007-5644
Lussumo Vanilla < 1.1.3 - Unauthenticated Unauthorized Sort Operations
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-5644. PoCs published by InATeam.
AI-analyzed exploit summary This PHP script exploits a blind SQL injection vulnerability in Vanilla Forum <= 1.1.3 via the /ajax/sortcategories.php endpoint. It uses time-based techniques (BENCHMARK) to extract user password hashes from the database.
Description
Lussumo Vanilla 1.1.3 and earlier does not require admin privileges for (1) ajax/sortcategories.php and (2) ajax/sortroles.php, which allows remote attackers to conduct unauthorized sort operations and other activities.
Exploits (1)
This PHP script exploits a blind SQL injection vulnerability in Vanilla Forum <= 1.1.3 via the /ajax/sortcategories.php endpoint. It uses time-based techniques (BENCHMARK) to extract user password hashes from the database.