Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-1089. PoCs published by kaMtiEz.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in phptroubleticket 2.0 (and possibly lower versions) via the 'id' parameter in vedi_faq.php. The PoC uses a UNION-based SQLi to extract email and password from the 'utenti' table.
Description
SQL injection vulnerability in vedi_faq.php in PHP Trouble Ticket 2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in phptroubleticket 2.0 (and possibly lower versions) via the 'id' parameter in vedi_faq.php. The PoC uses a UNION-based SQLi to extract email and password from the 'utenti' table.