Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-1919. PoCs published by Crackers_Child.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Apartment Search Script, allowing an attacker to extract admin credentials via a crafted UNION-based SQL query. The PoC provides specific URLs to retrieve the username and password from the 'site_admin' table.
Description
SQL injection vulnerability in listtest.php in YourFreeWorld Apartment Search Script allows remote attackers to execute arbitrary SQL commands via the r parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Apartment Search Script, allowing an attacker to extract admin credentials via a crafted UNION-based SQL query. The PoC provides specific URLs to retrieve the username and password from the 'site_admin' table.