CVE-2008-1551
RunCMS Photo Module 3.02 - SQL Injection via viewcat.php cid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1551. PoCs published by S@BUN.
AI-analyzed exploit summary This exploit demonstrates SQL injection in RunCMS Photo module 3.02, allowing unauthorized extraction of admin credentials via crafted UNION-based queries. The PoC provides direct URLs to leak usernames and passwords from the `runcms_users` table.
Description
SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitrary SQL commands via the cid parameter.
Exploits (1)
This exploit demonstrates SQL injection in RunCMS Photo module 3.02, allowing unauthorized extraction of admin credentials via crafted UNION-based queries. The PoC provides direct URLs to leak usernames and passwords from the `runcms_users` table.