Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-0498. PoCs published by D4m14n.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Bigware Shop 2.0, allowing an attacker to extract admin email addresses and password hashes via a crafted URL. The PoC targets the 'pollid' parameter in 'main_bigware_53.php' to perform a UNION-based SQL injection.
Description
SQL injection vulnerability in main_bigware_53.tpl.php in Bigware Shop 2.0 allows remote attackers to execute arbitrary SQL commands via the pollid parameter in a results action to main_bigware_53.php.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Bigware Shop 2.0, allowing an attacker to extract admin email addresses and password hashes via a crafted URL. The PoC targets the 'pollid' parameter in 'main_bigware_53.php' to perform a UNION-based SQL injection.