Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-5063. PoCs published by Darren McDonald.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in VWar 1.6.1 R2 via the 'ratearticleselect' parameter in a POST request. The payload uses the 'char()' function to bypass filters and inject arbitrary SQL commands.
Description
SQL injection vulnerability in article.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the ratearticleselect parameter.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in VWar 1.6.1 R2 via the 'ratearticleselect' parameter in a POST request. The payload uses the 'char()' function to bypass filters and inject arbitrary SQL commands.