Exploitation Summary
EIP tracks 1 public exploit for CVE-2012-4070. PoCs published by Daniel Correa.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Dir2web 3.0 via the 'oid' parameter in the URL. The payload bypasses authentication and retrieves sensitive information by manipulating the SQL query.
Description
SQL injection vulnerability in system/src/dispatcher.php in Dir2web 3.0 allows remote attackers to execute arbitrary SQL commands via the oid parameter in a homepage action to index.php.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in Dir2web 3.0 via the 'oid' parameter in the URL. The payload bypasses authentication and retrieves sensitive information by manipulating the SQL query.