CVE-2008-0692
iTechBids 3 Gold and 5.0 - SQL Injection via bidhistory.php item_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0692. PoCs published by QTRinux.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in iTechBids v3 Gold, allowing an attacker to extract admin credentials via a crafted UNION-based SQL query. The PoC provides a direct URL path and payload for exploitation.
Description
SQL injection vulnerability in bidhistory.php in iTechBids 3 Gold and 5.0 allows remote attackers to execute arbitrary SQL commands via the item_id parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in iTechBids v3 Gold, allowing an attacker to extract admin credentials via a crafted UNION-based SQL query. The PoC provides a direct URL path and payload for exploitation.