Exploitation Summary
EIP tracks 2 public exploits for CVE-2008-2688. PoCs published by Bl@ckbe@rD.
AI-analyzed exploit summary This exploit demonstrates SQL injection in Pilot Cart 7.3 via the 'article' parameter in 'pilot.asp'. It includes both union-based and blind SQL injection techniques to extract data from the 'msysobjects' table.
Description
SQL injection vulnerability in pilot.asp in ASPilot Pilot Cart 7.3 allows remote attackers to execute arbitrary SQL commands via the article parameter in a kb action.
Exploits (2)
This exploit demonstrates SQL injection in Pilot Cart 7.3 via the 'article' parameter in 'pilot.asp'. It includes both union-based and blind SQL injection techniques to extract data from the 'msysobjects' table.
This advisory details multiple vulnerabilities in ASPilot Pilot Cart 7.3, including SQL injection, XSS, iFrame injections, and link injections. It provides specific parameter names and affected pages but lacks functional exploit code.