CVE-2008-2125
Musicbox 2.3.6-2.3.7 - SQL Injection via viewalbums.php artistId Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-2125. PoCs published by snakespc, HaCkeR_EgY.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Musicbox Version 2.3.8, allowing an attacker to extract user credentials via a UNION-based SQL injection in the 'artistId' parameter.
Description
SQL injection vulnerability in viewalbums.php in Musicbox 2.3.6 and 2.3.7 allows remote attackers to execute arbitrary SQL commands via the artistId parameter.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in Musicbox Version 2.3.8, allowing an attacker to extract user credentials via a UNION-based SQL injection in the 'artistId' parameter.
This exploit demonstrates a SQL injection vulnerability in Musicbox versions 2.3.6 and 2.3.7 via the 'artistId' parameter in 'viewalbums.php'. The PoC uses a UNION-based SQLi to extract username and password from the 'users' table.