CVE-2010-1923
Hi Web Wiesbaden Web 2.0 Social Network Freunde Community System - SQL Injection via id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-1923. PoCs published by Easy Laster.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Web 2.0 Social Network Freunde Community System by injecting a UNION-based query to extract admin credentials. The PoC constructs a malicious URL that retrieves password and ID from the admin table.
Description
SQL injection vulnerability in user.php in Hi Web Wiesbaden Web 2.0 Social Network Freunde Community System allows remote attackers to execute arbitrary SQL commands via the id parameter in a showgallery action.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in Web 2.0 Social Network Freunde Community System by injecting a UNION-based query to extract admin credentials. The PoC constructs a malicious URL that retrieves password and ID from the admin table.