CVE-2008-2277
Feedback and Rating Script 1.0 - SQL Injection via detail.php listingid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2277. PoCs published by t0pP8uZz.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Feedback and Rating Script 1.0 via the 'listingid' parameter in detail.php. The PoC extracts admin credentials from the database by leveraging a UNION-based SQL injection technique.
Description
SQL injection vulnerability in detail.php in Feedback and Rating Script 1.0 allows remote attackers to execute arbitrary SQL commands via the listingid parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Feedback and Rating Script 1.0 via the 'listingid' parameter in detail.php. The PoC extracts admin credentials from the database by leveraging a UNION-based SQL injection technique.