Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-1715. PoCs published by NTOS-Team.
AI-analyzed exploit summary This exploit bypasses the security code in AuraCMS 2.x and injects an administrator account via SQL injection in the 'country' parameter. It leverages weak input validation and predictable security code generation.
Description
SQL injection vulnerability in content/user.php in AuraCMS 2.2.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the country parameter.
Exploits (1)
This exploit bypasses the security code in AuraCMS 2.x and injects an administrator account via SQL injection in the 'country' parameter. It leverages weak input validation and predictable security code generation.