Exploitation Summary
EIP tracks 1 public exploit for CVE-2007-6658. PoCs published by Pr0metheuS.
AI-analyzed exploit summary This exploit leverages a SQL injection vulnerability in CCMS v3.1 to extract MD5 password hashes from the database. It constructs a malicious SQL query via URL manipulation and retrieves the hash for a specified user ID.
Description
SQL injection vulnerability in admin.php/vars.php in CustomCMS (CCMS) 3.1 Demo allows remote attackers to execute arbitrary SQL commands via the p parameter in the Console page.
Exploits (1)
This exploit leverages a SQL injection vulnerability in CCMS v3.1 to extract MD5 password hashes from the database. It constructs a malicious SQL query via URL manipulation and retrieves the hash for a specified user ID.