CVE-2008-2504
Simpel Side Netbutik 1-4 - SQL Injection via cat or id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2504. PoCs published by Mr.SQL.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Netbutik versions 1-4, allowing attackers to extract user credentials (username and password) via union-based SQLi in the 'id' and 'cat' parameters.
Description
Multiple SQL injection vulnerabilities in Simpel Side Netbutik 1 through 4 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to netbutik.php and the (2) id parameter to product.php.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in Netbutik versions 1-4, allowing attackers to extract user credentials (username and password) via union-based SQLi in the 'id' and 'cat' parameters.