CVE-2008-2753
Pooya Site Builder 6.0 - SQL Injection via xslIdn or part Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2753. PoCs published by BugReport.IR.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Pooya Site Builder (PSB) version 6.0, specifically targeting the 'xslIdn' and 'part' parameters in multiple ASPX files. The PoC provides URLs to extract user credentials from the database.
Description
Multiple SQL injection vulnerabilities in Pooya Site Builder (PSB) 6.0 allow remote attackers to execute arbitrary SQL commands via the (1) xslIdn parameter to (a) utils/getXsl.aspx, and the (2) part parameter to (b) getXml.aspx and (c) getXls.aspx in utils/.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in Pooya Site Builder (PSB) version 6.0, specifically targeting the 'xslIdn' and 'part' parameters in multiple ASPX files. The PoC provides URLs to extract user credentials from the database.