Exploitation Summary
EIP tracks 2 public exploits for CVE-2010-1364. PoCs published by Easy Laster, 41.w4r10r.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Uiga Personal Portal's index.php. The PoC provides a crafted URL that extracts admin credentials via a UNION-based SQLi attack.
Description
SQL injection vulnerability in index.php in Uiga Personal Portal, as downloaded on 20100301, allows remote attackers to execute arbitrary SQL commands via the id parameter in a photos action. NOTE: some of these details are obtained from third party information.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in Uiga Personal Portal's index.php. The PoC provides a crafted URL that extracts admin credentials via a UNION-based SQLi attack.
This exploit demonstrates a SQL injection vulnerability in Uiga Personal Portal's index.php via the 'view' and 'exhort' parameters. It allows an attacker to extract sensitive information such as admin credentials from the database.