CVE-2008-2652
SMEWeb 1.4b and 1.4f - SQL Injection via idp and category Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2652. PoCs published by CWH Underground.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in SMEweb 1.4b. The SQLi requires magic_quotes_gpc to be off and allows extraction of user credentials, while the XSS affects multiple parameters across several scripts.
Description
Multiple SQL injection vulnerabilities in catalog.php in SMEWeb 1.4b and 1.4f allow remote attackers to execute arbitrary SQL commands via the (1) idp and (2) category parameters.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in SMEweb 1.4b. The SQLi requires magic_quotes_gpc to be off and allows extraction of user credentials, while the XSS affects multiple parameters across several scripts.