Exploitation Summary
EIP tracks 2 public exploits for CVE-2008-1430. PoCs published by xcorpitx.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in ASPapp KnowledgeBase via the 'catid' parameter in 'content_by_cat.asp'. It allows an attacker to extract user credentials (username, password, and access level) from the database.
Description
SQL injection vulnerability in links.asp in ASPapp allows remote attackers to execute arbitrary SQL commands via the CatId parameter.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in ASPapp KnowledgeBase via the 'catid' parameter in 'content_by_cat.asp'. It allows an attacker to extract user credentials (username, password, and access level) from the database.
This exploit demonstrates a SQL injection vulnerability in Iatek ASPapp's links.asp via the CatId parameter, allowing an attacker to extract user credentials, including those of high-privilege accounts like super-admin.