Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-4357. PoCs published by Beach.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in SiteEngine 7.1, allowing an attacker to extract user credentials from the database via union-based SQLi. It also describes a method to upload a backdoor through the administrator panel.
Description
SQL injection vulnerability in comments.php in SiteEngine 7.1 allows remote attackers to execute arbitrary SQL commands via the module parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in SiteEngine 7.1, allowing an attacker to extract user credentials from the database via union-based SQLi. It also describes a method to upload a backdoor through the administrator panel.