CVE-2008-2673
powie pNews 2.08 and 2.10 - SQL Injection via shownews Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2673. PoCs published by Cr@zy_King.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in pNews 2.08, allowing an attacker to extract sensitive information such as usernames and passwords from the database. The PoC uses a UNION-based SQL injection to retrieve data from the 'table' table.
Description
SQL injection vulnerability in index.php in Powie pNews 2.08 and 2.10, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the shownews parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in pNews 2.08, allowing an attacker to extract sensitive information such as usernames and passwords from the database. The PoC uses a UNION-based SQL injection to retrieve data from the 'table' table.