CVE-2008-2678
Telephone Directory 2008 - SQL Injection via code or id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2678. PoCs published by CWH Underground.
AI-analyzed exploit summary The exploit demonstrates SQL injection and XSS vulnerabilities in Telephone Directory 2008. It provides specific payloads for SQLi in 'edit1.php' and 'view_more.php', and an XSS vector in 'edit1.php'.
Description
Multiple SQL injection vulnerabilities in Telephone Directory 2008, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) code parameter in a confirm_data action to edit1.php and the (2) id parameter to view_more.php.
Exploits (1)
The exploit demonstrates SQL injection and XSS vulnerabilities in Telephone Directory 2008. It provides specific payloads for SQLi in 'edit1.php' and 'view_more.php', and an XSS vector in 'edit1.php'.