Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-2047. PoCs published by U238.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in Angelo-Emlak v1.0. The SQLi allows unauthorized extraction of admin credentials, while the XSS can execute arbitrary JavaScript in the context of the admin panel.
Description
Multiple SQL injection vulnerabilities in Angelo-Emlak 1.0 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) hpz/profil.asp and (2) hpz/prodetail.asp.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in Angelo-Emlak v1.0. The SQLi allows unauthorized extraction of admin credentials, while the XSS can execute arbitrary JavaScript in the context of the admin panel.