Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-0430. PoCs published by Ded MustD!e.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in 360 Web Manager CMS, allowing an attacker to extract user credentials (name and password) via a UNION-based SQLi attack. The exploit constructs a malicious URL that retrieves data from the 'user' table.
Description
SQL injection vulnerability in form.php in 360 Web Manager 3.0 allows remote attackers to execute arbitrary SQL commands via the IDFM parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in 360 Web Manager CMS, allowing an attacker to extract user credentials (name and password) via a UNION-based SQLi attack. The exploit constructs a malicious URL that retrieves data from the 'user' table.