Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-4776. PoCs published by Cru3l.b0y.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Pre Online Tests Generator Pro, allowing an attacker to extract admin credentials via a crafted URL. The payload uses a UNION-based SQLi to dump user_name and user_pass from the admin table.
Description
SQL injection vulnerability in takefreestart.php in PreProjects Pre Online Tests Generator Pro allows remote attackers to execute arbitrary SQL commands via the tid2 parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Pre Online Tests Generator Pro, allowing an attacker to extract admin credentials via a crafted URL. The payload uses a UNION-based SQLi to dump user_name and user_pass from the admin table.