CVE-2008-0187
SAM Broadcaster samPHPweb - SQL Injection via songid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0187. PoCs published by BackDoor.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in samPHPweb's songinfo.php script. It uses a UNION-based attack to extract sensitive data such as user passwords and MySQL version from the mysql.user table.
Description
SQL injection vulnerability in songinfo.php in SAM Broadcaster samPHPweb, possibly 4.2.2 and earlier, allows remote attackers to execute arbitrary SQL commands via the songid parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in samPHPweb's songinfo.php script. It uses a UNION-based attack to extract sensitive data such as user passwords and MySQL version from the mysql.user table.