Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-1327. PoCs published by Lucas Apa.
AI-analyzed exploit summary The provided text describes SQL injection and HTML injection vulnerabilities in TornadoStore 1.4.3, with example URIs demonstrating the SQLi vectors. No actual exploit code is present, only a vulnerability description and proof-of-concept URIs.
Description
Multiple SQL injection vulnerabilities in TornadoStore 1.4.3 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the marca parameter to precios.php3 or (2) the where parameter in a delivery_courier action to control/abm_list.php3.
Exploits (1)
The provided text describes SQL injection and HTML injection vulnerabilities in TornadoStore 1.4.3, with example URIs demonstrating the SQLi vectors. No actual exploit code is present, only a vulnerability description and proof-of-concept URIs.