This exploit demonstrates a remote SQL injection vulnerability in PrideForum 1.0 via the 'forum.asp' page. The crafted URL injects a UNION-based SQL query to extract admin credentials (ID, username, and password) from the 'adminlogins' table.
Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:PrideForum 1.0
No auth needed
Prerequisites:Target must be running PrideForum 1.0 · The 'forum.asp' page must be accessible