Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-6393. PoCs published by t0pP8uZz.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Ace Image Hosting Script, allowing an attacker to extract user credentials from the database. The payload uses a UNION-based SQLi to retrieve the admin username and password in plaintext.
Description
SQL injection vulnerability in albums.php in Ace Image Hosting Script allows remote authenticated users to execute arbitrary SQL commands via the id parameter in editalbum mode.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Ace Image Hosting Script, allowing an attacker to extract user credentials from the database. The payload uses a UNION-based SQLi to retrieve the admin username and password in plaintext.