Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-0129. PoCs published by EgiX.
AI-analyzed exploit summary This is a functional blind SQL injection exploit for Site@School <= 2.3.10, targeting the 'album_name' parameter in slideshow_full.php. It retrieves user credentials by brute-forcing character-by-character via boolean-based SQLi.
Description
SQL injection vulnerability in starnet/addons/slideshow_full.php in Site@School 2.3.10 and earlier allows remote attackers to execute arbitrary SQL commands via the album_name parameter.
Exploits (1)
This is a functional blind SQL injection exploit for Site@School <= 2.3.10, targeting the 'album_name' parameter in slideshow_full.php. It retrieves user credentials by brute-forcing character-by-character via boolean-based SQLi.