CVE-2008-0429
AlstraSoft Forum Pay Per Post Exchange 2.0 - SQL Injection via catid Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-0429. PoCs published by r45c4l, t0pP8uZz.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Alstrasoft Forum via the 'catid' parameter in the 'forum_catview' menu. It allows an attacker to extract admin and user credentials by manipulating the SQL query through a UNION-based attack.
Description
SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange 2.0 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a forum_catview action.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in Alstrasoft Forum via the 'catid' parameter in the 'forum_catview' menu. It allows an attacker to extract admin and user credentials by manipulating the SQL query through a UNION-based attack.
This exploit demonstrates SQL injection vulnerabilities in Forum Pay Per Post, allowing an attacker to extract admin and user credentials from the database. The PoC provides specific URLs to retrieve plaintext passwords and other sensitive information.