CVE-2008-0278
x7_chat < 2.0.5 - SQL Injection via Day Parameter in sm_window Action
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0278. PoCs published by nonroot.
AI-analyzed exploit summary This exploit targets a SQL injection vulnerability in x7chat 2.0.5, extracting usernames and password hashes via crafted UNION-based SQL queries. It automates the process by fetching data from the vulnerable endpoint and saving it to a file.
Description
SQL injection vulnerability in index.php in X7 Chat 2.0.5 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the day parameter in a sm_window action.
Exploits (1)
This exploit targets a SQL injection vulnerability in x7chat 2.0.5, extracting usernames and password hashes via crafted UNION-based SQL queries. It automates the process by fetching data from the vulnerable endpoint and saving it to a file.