CVE-2007-6159
Tilde CMS 4.x and earlier - SQL Injection via aarstal Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-6159. PoCs published by KiNgOfThEwOrLd.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in Tilde CMS <= v. 4.x via the 'aarstal' parameter. It includes proof-of-concept URLs for extracting database information and executing arbitrary SQL queries.
Description
SQL injection vulnerability in index.php in Tilde CMS 4.x and earlier allows remote attackers to execute arbitrary SQL commands via the aarstal parameter in a yeardetail action, a different vector than CVE-2006-1500.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in Tilde CMS <= v. 4.x via the 'aarstal' parameter. It includes proof-of-concept URLs for extracting database information and executing arbitrary SQL queries.