CVE-2008-2087
Softbiz Web Hosting Directory Script - SQL Injection via search_result.php host_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2087. PoCs published by K-159.
AI-analyzed exploit summary This exploit demonstrates a blind SQL injection vulnerability in Softbiz Web Host Directory Script via the 'host_id' parameter in search_result.php. It allows remote attackers to extract admin credentials in plain text when magic_quotes is disabled.
Description
SQL injection vulnerability in search_result.php in Softbiz Web Host Directory Script, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the host_id parameter, a different vector than CVE-2005-3817.
Exploits (1)
This exploit demonstrates a blind SQL injection vulnerability in Softbiz Web Host Directory Script via the 'host_id' parameter in search_result.php. It allows remote attackers to extract admin credentials in plain text when magic_quotes is disabled.