CVE-2008-0546
CandyPress 4.1.1.26 - SQL Injection via idProduct or options Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0546. PoCs published by BugReport.IR.
AI-analyzed exploit summary The exploit demonstrates SQL injection, XSS, and path disclosure vulnerabilities in CandyPress eCommerce suite version 4.1.1.26. It includes functional PoC URLs to extract sensitive data such as admin credentials, payment details, and configuration settings.
Description
Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers to execute arbitrary SQL commands via the (1) idProduct and (2) options parameters to (a) ajax/ajax_optInventory.asp, or the (2) recid parameter to (b) ajax/ajax_getBrands.asp.
Exploits (1)
The exploit demonstrates SQL injection, XSS, and path disclosure vulnerabilities in CandyPress eCommerce suite version 4.1.1.26. It includes functional PoC URLs to extract sensitive data such as admin credentials, payment details, and configuration settings.