Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-4869. PoCs published by ZonTa.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in DBHcms 1.1.4, allowing an attacker to extract user credentials via a crafted URL parameter. The PoC uses a UNION-based SQLi to dump login and password hashes from the database.
Description
SQL injection vulnerability in index.php in DBHcms 1.1.4 allows remote attackers to execute arbitrary SQL commands via the editmenu parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in DBHcms 1.1.4, allowing an attacker to extract user credentials via a crafted URL parameter. The PoC uses a UNION-based SQLi to dump login and password hashes from the database.