Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-2781. PoCs published by Ali Jasbi.
AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in DZOIC Handshakes 3.5, where user-supplied input in the 'fname' parameter is not properly sanitized. The exploit example demonstrates how an attacker could inject malicious SQL queries via the URL.
Description
SQL injection vulnerability in index.php in DZOIC Handshakes 3.5 allows remote attackers to execute arbitrary SQL commands via the fname parameter in a members search action.
Exploits (1)
The provided text describes an SQL injection vulnerability in DZOIC Handshakes 3.5, where user-supplied input in the 'fname' parameter is not properly sanitized. The exploit example demonstrates how an attacker could inject malicious SQL queries via the URL.