CVE-2010-4851
Eclime 1.1.2b - SQL Injection via ref poll_id or country Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-4851. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary The exploit demonstrates multiple SQL injection and XSS vulnerabilities in Eclime 1.1.2b. It includes PoC examples for injecting arbitrary SQL code via the 'ref', 'poll_id', and 'country' parameters, as well as an XSS payload via the 'reason' parameter in login.php.
Description
Multiple SQL injection vulnerabilities in Eclime 1.1.2b allow remote attackers to execute arbitrary SQL commands via the (1) ref or (2) poll_id parameter to index.php, or the (3) country parameter to create_account.php.
Exploits (1)
The exploit demonstrates multiple SQL injection and XSS vulnerabilities in Eclime 1.1.2b. It includes PoC examples for injecting arbitrary SQL code via the 'ref', 'poll_id', and 'country' parameters, as well as an XSS payload via the 'reason' parameter in login.php.