Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-2425. PoCs published by His0k4.
AI-analyzed exploit summary This Perl script exploits a blind SQL injection vulnerability (CVE-2008-2425) by injecting malicious SQL queries into a vulnerable parameter. It uses time-based or content-based blind SQLi techniques to extract data such as database contents or files from the target system.
Description
SQL injection vulnerability in index.php in FicHive 1.0 allows remote attackers to execute arbitrary SQL commands via the letter parameter in a Search action, a different vector than CVE-2008-2416. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This Perl script exploits a blind SQL injection vulnerability (CVE-2008-2425) by injecting malicious SQL queries into a vulnerable parameter. It uses time-based or content-based blind SQLi techniques to extract data such as database contents or files from the target system.