Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-1915. PoCs published by U238.
AI-analyzed exploit summary This exploit demonstrates SQL injection in BlogWorx's 'view.asp' by injecting UNION-based queries to extract user credentials (UserName, Password) from the 'Users' table. The PoC provides direct URLs to exploit the vulnerability without requiring authentication.
Description
SQL injection vulnerability in view.asp in DevWorx BlogWorx 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
This exploit demonstrates SQL injection in BlogWorx's 'view.asp' by injecting UNION-based queries to extract user credentials (UserName, Password) from the 'Users' table. The PoC provides direct URLs to exploit the vulnerability without requiring authentication.