Exploitation Summary
EIP tracks 2 public exploits for CVE-2010-2687. PoCs published by CoBRa_21.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Boat Classifieds' printdetail.asp via the Id parameter. It includes test cases for true (1=1) and false (1=2) conditions to confirm vulnerability.
Description
SQL injection vulnerability in printdetail.asp in Site2Nite Boat Classifieds allows remote attackers to execute arbitrary SQL commands via the Id parameter.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in Boat Classifieds' printdetail.asp via the Id parameter. It includes test cases for true (1=1) and false (1=2) conditions to confirm vulnerability.
This is a functional SQL injection exploit for Boat Classifieds, leveraging a UNION-based attack to extract username and password from the 'tbllogin' table. The payload bypasses authentication by appending a tautological condition ('having 1=1--').