CVE-2010-0673
Copperleaf Photolog 0.16 - SQL Injection via postid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-0673. PoCs published by kaMtiEz.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in WordPress Copperleaf Photolog plugin (version 0.16 or lower). The PoC uses a UNION-based SQLi to extract user credentials from the `wp_users` table.
Description
SQL injection vulnerability in cplphoto.php in the Copperleaf Photolog plugin 0.16, and possibly earlier, for WordPress allows remote attackers to execute arbitrary SQL commands via the postid parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in WordPress Copperleaf Photolog plugin (version 0.16 or lower). The PoC uses a UNION-based SQLi to extract user credentials from the `wp_users` table.