Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-6137. PoCs published by S.W.A.T..
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Content Injector v1.52, allowing an attacker to extract admin credentials (username and MD5 password) via a crafted UNION-based SQL query.
Description
SQL injection vulnerability in news.php in Content Injector 1.52 allows remote attackers to execute arbitrary SQL commands via the cat parameter to index.php. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Content Injector v1.52, allowing an attacker to extract admin credentials (username and MD5 password) via a crafted UNION-based SQL query.