Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-3467. PoCs published by _mRkZ_.
AI-analyzed exploit summary This Perl script exploits a blind SQL injection vulnerability in E-Xoopport Samsara <= v3.1 via the Sections Module. It authenticates, retrieves a section ID, and extracts a user's password hash via time-based SQLi.
Description
SQL injection vulnerability in modules/sections/index.php in E-Xoopport Samsara 3.1 and earlier, when the Tutorial module is enabled, allows remote attackers to execute arbitrary SQL commands via the secid parameter in a listarticles action.
Exploits (1)
This Perl script exploits a blind SQL injection vulnerability in E-Xoopport Samsara <= v3.1 via the Sections Module. It authenticates, retrieves a section ID, and extracts a user's password hash via time-based SQLi.