Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-1272. PoCs published by xcorpitx.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in BM Classifieds via the 'listingid' and 'ad' parameters. It extracts user credentials (username, email, password) from the 'users' table using UNION-based SQLi techniques.
Description
Multiple SQL injection vulnerabilities in BM Classifieds 20080309 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to showad.php and the (2) ad parameter to pfriendly.php.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in BM Classifieds via the 'listingid' and 'ad' parameters. It extracts user credentials (username, email, password) from the 'users' table using UNION-based SQLi techniques.