CVE-2010-4860
MyPhpAuction 2010 - SQL Injection via product_desc.php id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-4860. PoCs published by h4ck3r.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in MyPhpAuction 2010, allowing an attacker to extract admin credentials via a crafted UNION-based query. The PoC targets the 'id' parameter in 'product_desc.php' to dump the admin username and password.
Description
SQL injection vulnerability in product_desc.php in MyPhpAuction 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in MyPhpAuction 2010, allowing an attacker to extract admin credentials via a crafted UNION-based query. The PoC targets the 'id' parameter in 'product_desc.php' to dump the admin username and password.