Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-0099. PoCs published by The:Paradox.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in MyPHP Forum v3.0 (Final) and possibly lower versions. The vulnerability arises due to improper sanitization of the `$searchtext` parameter in `search.php`, allowing attackers to inject malicious SQL queries even when Magic Quotes is enabled.
Description
Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the searchtext parameter to search.php, and unspecified other vectors.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in MyPHP Forum v3.0 (Final) and possibly lower versions. The vulnerability arises due to improper sanitization of the `$searchtext` parameter in `search.php`, allowing attackers to inject malicious SQL queries even when Magic Quotes is enabled.