Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-1054. PoCs published by Isfahan.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Pars CMS by injecting a UNION-based query to extract data from the database. The vulnerability arises from insufficient sanitization of user-supplied input in the 'RP' parameter.
Description
Multiple SQL injection vulnerabilities in ParsCMS allow remote attackers to execute arbitrary SQL commands via the RP parameter to (1) fa_default.asp and (2) en_default.asp.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Pars CMS by injecting a UNION-based query to extract data from the database. The vulnerability arises from insufficient sanitization of user-supplied input in the 'RP' parameter.