CVE-2010-2462
OroHYIP - SQL Injection via withdraw_money.php id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-2462. PoCs published by L0rd CrusAd3r.
AI-analyzed exploit summary This is a writeup describing an SQL injection vulnerability in OroHYIP version 1. The vulnerability is located in the 'withdraw_money.php' script, specifically in the 'id' parameter when the 'a' parameter is set to 'cancel'.
Description
SQL injection vulnerability in withdraw_money.php in Toma Cero OroHYIP allows remote attackers to execute arbitrary SQL commands via the id parameter in a cancel action.
Exploits (1)
This is a writeup describing an SQL injection vulnerability in OroHYIP version 1. The vulnerability is located in the 'withdraw_money.php' script, specifically in the 'id' parameter when the 'a' parameter is set to 'cancel'.