CVE-2008-1870
PIGMy-SQL <= 1.4.1 - SQL Injection via getdata.php id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1870. PoCs published by t0pP8uZz.
AI-analyzed exploit summary This Perl script exploits a blind SQL injection vulnerability in PIGMy-SQL <= 1.4.1 by brute-forcing the admin credentials via ASCII character extraction. It tests for vulnerability by comparing responses to true/false conditions and then extracts the username and password from the database.
Description
SQL injection vulnerability in getdata.php in PIGMy-SQL 1.4.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
This Perl script exploits a blind SQL injection vulnerability in PIGMy-SQL <= 1.4.1 by brute-forcing the admin credentials via ASCII character extraction. It tests for vulnerability by comparing responses to true/false conditions and then extracts the username and password from the database.