CVE-2010-1599
nkinfoweb 2.5 and 5.2.2.0 - SQL Injection via loadorder.php id_sp Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-1599. PoCs published by d4rk-h4ck3r.
AI-analyzed exploit summary This Perl script exploits a SQL injection vulnerability in NKINFOWEB VSp © 2009 by injecting a malicious SQL query into the 'id_sp' parameter of 'loadorder.php'. It extracts admin credentials from the 'usersys' table and displays them.
Description
SQL injection vulnerability in loadorder.php in NKInFoWeb 2.5 and 5.2.2.0 allows remote attackers to execute arbitrary SQL commands via the id_sp parameter.
Exploits (1)
This Perl script exploits a SQL injection vulnerability in NKINFOWEB VSp © 2009 by injecting a malicious SQL query into the 'id_sp' parameter of 'loadorder.php'. It extracts admin credentials from the 'usersys' table and displays them.