Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-2688. PoCs published by Sangteamtham.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Boat Classifieds software, allowing an attacker to extract username and password from the 'tbllogin' table via a UNION-based attack. The payload is appended to the 'ID' parameter in the 'detail.asp' page.
Description
SQL injection vulnerability in detail.asp in Site2Nite Boat Classifieds allows remote attackers to execute arbitrary SQL commands via the ID parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Boat Classifieds software, allowing an attacker to extract username and password from the 'tbllogin' table via a UNION-based attack. The payload is appended to the 'ID' parameter in the 'detail.asp' page.