Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-1049. PoCs published by Sioma Labs.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in Uiga Business Portal. The SQLi allows unauthorized data extraction from user and admin tables, while the XSS can be triggered via the comment box.
Description
Multiple SQL injection vulnerabilities in Uiga Business Portal allow remote attackers to execute arbitrary SQL commands via the (1) noentryid parameter to blog/index.php and the (2) p parameter to index2.php.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in Uiga Business Portal. The SQLi allows unauthorized data extraction from user and admin tables, while the XSS can be triggered via the comment box.