Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-107343. PoCs published by t0pP8uZz.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Gaming Directory 1.0, allowing an attacker to read arbitrary files from the server using MySQL's `load_file` function. The provided URL manipulates the `cat_id` parameter to inject a UNION-based SQL query that attempts to read `/etc/passwd`.
Description
Gaming Directory 1.0 - 'cat_id' SQL Injection
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Gaming Directory 1.0, allowing an attacker to read arbitrary files from the server using MySQL's `load_file` function. The provided URL manipulates the `cat_id` parameter to inject a UNION-based SQL query that attempts to read `/etc/passwd`.