CVE-2010-4912
UCenter Home 2.0 - SQL Injection via shop.php shopid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-4912. PoCs published by KnocKout.
AI-analyzed exploit summary This exploit demonstrates a MySQL error-based SQL injection vulnerability in UCenter Home 2.0 via the 'shopid' parameter in shop.php. It extracts database names and user credentials using hex conversion and concatenation techniques.
Description
SQL injection vulnerability in shop.php in UCenter Home 2.0 allows remote attackers to execute arbitrary SQL commands via the shopid parameter in a view action.
Exploits (1)
This exploit demonstrates a MySQL error-based SQL injection vulnerability in UCenter Home 2.0 via the 'shopid' parameter in shop.php. It extracts database names and user credentials using hex conversion and concatenation techniques.