Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-0856. PoCs published by Khashayar Fereidani.
AI-analyzed exploit summary This exploit demonstrates SQL injection and remote file upload vulnerabilities in eVision 2.0. It includes blind SQLi, union-based SQLi, and a file upload form to achieve remote code execution.
Description
Multiple SQL injection vulnerabilities in e-Vision CMS 2.02 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) iframe.php and (2) print.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This exploit demonstrates SQL injection and remote file upload vulnerabilities in eVision 2.0. It includes blind SQLi, union-based SQLi, and a file upload form to achieve remote code execution.