CVE-2008-2189
AnServ Auction XL - SQL Injection via viewfaqs.php cat Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2189. PoCs published by K-159.
AI-analyzed exploit summary This exploit demonstrates a blind SQL injection vulnerability in Anserv Auction XL's viewfaqs.php via the 'cat' parameter. It allows remote attackers to extract admin credentials (username and MD5 password hash) when magic_quotes is disabled.
Description
SQL injection vulnerability in viewfaqs.php in AnServ Auction XL allows remote attackers to execute arbitrary SQL commands via the cat parameter.
Exploits (1)
This exploit demonstrates a blind SQL injection vulnerability in Anserv Auction XL's viewfaqs.php via the 'cat' parameter. It allows remote attackers to extract admin credentials (username and MD5 password hash) when magic_quotes is disabled.