Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-4916. PoCs published by mr_me.
AI-analyzed exploit summary This exploit demonstrates a blind SQL injection vulnerability in ColdUserGroup v1.6 via the 'LibraryID' parameter in index.cfm. It extracts database user and name by brute-forcing ASCII characters and checking for a true condition string.
Description
Multiple SQL injection vulnerabilities in index.cfm in ColdGen ColdUserGroup 1.06 allow remote attackers to execute arbitrary SQL commands via the (1) ArticleID or (2) LibraryID parameter.
Exploits (1)
This exploit demonstrates a blind SQL injection vulnerability in ColdUserGroup v1.6 via the 'LibraryID' parameter in index.cfm. It extracts database user and name by brute-forcing ASCII characters and checking for a true condition string.