Exploitation Summary
EIP tracks 1 public exploit for CVE-2012-1210. PoCs published by indoushka.
AI-analyzed exploit summary The provided text describes a cross-site scripting (XSS) and SQL injection vulnerability in pfile 1.02, with an example URL demonstrating the SQLi exploit. It lacks executable code, making it a writeup rather than a functional PoC.
Description
SQL injection vulnerability in pfile/file.php in Powie pFile 1.02 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
The provided text describes a cross-site scripting (XSS) and SQL injection vulnerability in pfile 1.02, with an example URL demonstrating the SQLi exploit. It lacks executable code, making it a writeup rather than a functional PoC.