CVE-2010-2133
My Little Forum - SQL Injection via Contact.php ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-2133. PoCs published by Easy Laster.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in my little forum's contact.php. It allows an attacker to extract user credentials by manipulating the 'id' parameter with a UNION-based SQL injection payload.
Description
SQL injection vulnerability in contact.php in My Little Forum allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-2942.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in my little forum's contact.php. It allows an attacker to extract user credentials by manipulating the 'id' parameter with a UNION-based SQL injection payload.