Exploitation Summary
EIP tracks 1 public exploit for CVE-2012-4996. PoCs published by Ali Raheem.
AI-analyzed exploit summary The writeup describes SQL injection vulnerabilities in RivetTracker <=1.03, specifically in files like dltorrent.php and torrent_functions.php, which allow arbitrary SQL queries and potential file disclosure or code execution depending on database privileges.
Description
Multiple SQL injection vulnerabilities in RivetTracker 1.03 and earlier allow remote attackers to execute arbitrary SQL commands via the hash parameter to (1) dltorrent.php or (2) torrent_functions.php.
Exploits (1)
The writeup describes SQL injection vulnerabilities in RivetTracker <=1.03, specifically in files like dltorrent.php and torrent_functions.php, which allow arbitrary SQL queries and potential file disclosure or code execution depending on database privileges.