Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-1641. PoCs published by RMx.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in EfesTECH Video 5.0 by injecting a UNION-based query to extract user credentials (username, email, and password) from the 'uyeler' table. The vulnerability arises from insufficient input sanitization in the 'catID' parameter.
Description
SQL injection vulnerability in default.asp in EfesTECH Video 5.0 allows remote attackers to execute arbitrary SQL commands via the catID parameter.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in EfesTECH Video 5.0 by injecting a UNION-based query to extract user credentials (username, email, and password) from the 'uyeler' table. The vulnerability arises from insufficient input sanitization in the 'catID' parameter.