Exploitation Summary
EIP tracks 2 public exploits for CVE-2008-1349. PoCs published by DreamTurk, S@BUN.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in the 'bamagalerie3' module of RUNCMS 1.1A. The PoC provides specific SQL injection payloads to extract user credentials (username and password) from the 'runcms_users' table.
Description
SQL injection vulnerability in viewcat.php in the bamaGalerie (Bama Galerie) 3.03 and 3.041 module for eXV2 2.0.6 allows remote attackers to execute arbitrary SQL commands via the cid parameter.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in the 'bamagalerie3' module of RUNCMS 1.1A. The PoC provides specific SQL injection payloads to extract user credentials (username and password) from the 'runcms_users' table.
This exploit demonstrates a SQL injection vulnerability in eXV2 Module bamaGalerie 3.03. The exploit uses a UNION-based SQL injection to extract username and password hashes from the e_xoops_users table.