CVE-2008-1176
Affiliate Market 0.1 BETA - Cross-Site Scripting via sideblock4 Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1176. PoCs published by Khashayar Fereidani.
AI-analyzed exploit summary This Perl script exploits a SQL injection vulnerability in Affiliate Market Ver.0.1 BETA to extract admin credentials from the database. It constructs a malicious SQL query to retrieve usernames and passwords from the 'admin' table.
Description
Cross-site scripting (XSS) vulnerability in function/sideblock.php in Affiliate Market (affmarket) 0.1 BETA allows remote attackers to inject arbitrary web script or HTML via the sideblock4 parameter.
Exploits (1)
This Perl script exploits a SQL injection vulnerability in Affiliate Market Ver.0.1 BETA to extract admin credentials from the database. It constructs a malicious SQL query to retrieve usernames and passwords from the 'admin' table.