Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-2340. PoCs published by GoLd_M.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in News Manager 2.0, including remote file inclusion, file disclosure, SQL injection, permission bypass, and information leakage via PHPINFO. It provides specific endpoints and payloads for exploitation.
Description
Multiple SQL injection vulnerabilities in News Manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) lang parameter to (a) advsearch.php, (b) archive.php, and (c) index.php, and the (2) pid parameter to (d) list_tagitems.php.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in News Manager 2.0, including remote file inclusion, file disclosure, SQL injection, permission bypass, and information leakage via PHPINFO. It provides specific endpoints and payloads for exploitation.