Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-6106. PoCs published by K-159.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in alstrasoft E-Friends <= 4.98 via the 'seid' parameter. It allows retrieval of admin session IDs and user credentials (md5 hashes) through crafted SQL queries.
Description
SQL injection vulnerability in index.php in AlstraSoft E-Friends 4.98 and earlier allows remote attackers to execute arbitrary SQL commands via the seid parameter in a viewevent action.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in alstrasoft E-Friends <= 4.98 via the 'seid' parameter. It allows retrieval of admin session IDs and user credentials (md5 hashes) through crafted SQL queries.