CVE-2008-1759
jeuxflash_module for KwsPHP - SQL Injection via cat Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1759. PoCs published by Houssamix.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in KwsPHP's jeuxflash module, allowing an attacker to extract user credentials (pseudo and pass) from the database via a crafted UNION-based SQL query.
Description
SQL injection vulnerability in the jeuxflash module for KwsPHP allows remote attackers to execute arbitrary SQL commands via the cat parameter to index.php, a different vector than CVE-2007-4922.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in KwsPHP's jeuxflash module, allowing an attacker to extract user credentials (pseudo and pass) from the database via a crafted UNION-based SQL query.