Exploitation Summary
EIP tracks 2 public exploits for CVE-2008-2789.
PoCs published by Mr.SQL, including Metasploit module exploits/windows/fileformat/xradio_xrl_sehbof.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in BaSiC-CMS via the 'page_id' parameter in index.php. The PoC uses a UNION-based SQLi to extract database version, current user, and database name.
Description
SQL injection vulnerability in pages/index.php in BASIC-CMS allows remote attackers to execute arbitrary SQL commands via the page_id parameter.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in BaSiC-CMS via the 'page_id' parameter in index.php. The PoC uses a UNION-based SQLi to extract database version, current user, and database name.
This Metasploit module exploits a buffer overflow in xRadio 0.95b via a crafted .xrl file, leveraging SEH overwrite and an egghunter for reliable payload execution. The exploit targets a universal Windows vulnerability with a known return address.