Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-6656. PoCs published by EgiX.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in CMS Made Simple <= 1.2.2 via the TinyMCE module. The 'templateid' parameter is not properly sanitized, allowing an attacker to inject malicious SQL queries to extract sensitive data like usernames and passwords.
Description
SQL injection vulnerability in content_css.php in the TinyMCE module for CMS Made Simple 1.2.2 and earlier allows remote attackers to execute arbitrary SQL commands via the templateid parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in CMS Made Simple <= 1.2.2 via the TinyMCE module. The 'templateid' parameter is not properly sanitized, allowing an attacker to inject malicious SQL queries to extract sensitive data like usernames and passwords.