CVE-2008-2263
Automated Link Exchange Portal - SQL Injection via cat_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2263. PoCs published by HaCkeR_EgY.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Linkspile's link.php, allowing an attacker to extract user credentials (fname, password, email) from the lp_user_tb table via a crafted UNION-based query.
Description
SQL injection vulnerability in linking.page.php in Automated Link Exchange Portal allows remote attackers to execute arbitrary SQL commands via the cat_id parameter. NOTE: linking.page.php is commonly renamed to link.php, links.php, etc.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Linkspile's link.php, allowing an attacker to extract user credentials (fname, password, email) from the lp_user_tb table via a crafted UNION-based query.