Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-6127. PoCs published by tomplixsee.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in Project Alumni v1.0.9 and lower. The SQLi allows unauthorized data extraction, including admin credentials, while the XSS enables arbitrary script execution in the context of the victim's browser.
Description
Multiple SQL injection vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the year parameter to (1) view.page.inc.php, which is reachable through a view action to index.php; or (2) the year parameter to news.page.inc.php, which is reachable through a news action to index.php.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in Project Alumni v1.0.9 and lower. The SQLi allows unauthorized data extraction, including admin credentials, while the XSS enables arbitrary script execution in the context of the victim's browser.