CVE-2008-0911
iScripts MultiCart 2.0 - Authenticated SQL Injection via productid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0911. PoCs published by t0pP8uZz.
AI-analyzed exploit summary This is a client-side JavaScript exploit for a blind SQL injection vulnerability in MultiCart 2.0. It automates the extraction of admin credentials by brute-forcing ASCII characters via HTTP requests to the vulnerable 'productdetails.php' endpoint.
Description
SQL injection vulnerability in productdetails.php in iScripts MultiCart 2.0 allows remote authenticated users to execute arbitrary SQL commands via the productid parameter.
Exploits (1)
This is a client-side JavaScript exploit for a blind SQL injection vulnerability in MultiCart 2.0. It automates the extraction of admin credentials by brute-forcing ASCII characters via HTTP requests to the vulnerable 'productdetails.php' endpoint.