Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-0186. PoCs published by Virangar Security.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in NetRisk 1.9.7. The SQLi allows retrieval of admin credentials via union-based injection, while the XSS executes arbitrary JavaScript.
Description
Cross-site scripting (XSS) vulnerability in index.php in NetRisk 1.9.7 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter, possibly related to CVE-2008-0144.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in NetRisk 1.9.7. The SQLi allows retrieval of admin credentials via union-based injection, while the XSS executes arbitrary JavaScript.