CVE-2008-2536
YABSoft Advanced Image Hosting Script < 2.1 - SQL Injection via out.php t Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2536. PoCs published by Stack.
AI-analyzed exploit summary This Perl script exploits a SQL injection vulnerability in Advanced Image Host Script (AIH) v2.1 to extract admin credentials. It crafts a malicious SQL query via the 't' parameter in 'out.php' to retrieve the username and password from the 'setting' table.
Description
SQL injection vulnerability in out.php in YABSoft Advanced Image Hosting (AIH) Script 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the t parameter.
Exploits (1)
This Perl script exploits a SQL injection vulnerability in Advanced Image Host Script (AIH) v2.1 to extract admin credentials. It crafts a malicious SQL query via the 't' parameter in 'out.php' to retrieve the username and password from the 'setting' table.