Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-2629. PoCs published by DreamTurk.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in pLog by manipulating the 'albumId' parameter to extract user credentials from the 'plog_users' table. The attack leverages a UNION-based SQLi technique to bypass authentication.
Description
SQL injection vulnerability in the LifeType (formerly pLog) module for Drupal allows remote attackers to execute arbitrary SQL commands via the albumId parameter in a ViewAlbum action to index.php.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in pLog by manipulating the 'albumId' parameter to extract user credentials from the 'plog_users' table. The attack leverages a UNION-based SQLi technique to bypass authentication.