Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-4856. PoCs published by ZoRLu.
AI-analyzed exploit summary This Python script exploits a SQL injection vulnerability in xWeblog v2.2 via the 'arsiv.asp' page's 'tarih' parameter to extract user credentials (AD and SIFRE) from the 'uyeler' table. It constructs malicious SQL queries and parses the response to display the extracted data.
Description
SQL injection vulnerability in arsiv.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the tarih parameter.
Exploits (1)
This Python script exploits a SQL injection vulnerability in xWeblog v2.2 via the 'arsiv.asp' page's 'tarih' parameter to extract user credentials (AD and SIFRE) from the 'uyeler' table. It constructs malicious SQL queries and parses the response to display the extracted data.