CVE-2008-2815
MyMarket 1.72 - SQL Injection via Shopping Index ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2815. PoCs published by anonymous.
AI-analyzed exploit summary This Perl script exploits a blind SQL injection vulnerability in MyMarket 1.72 by brute-forcing the length and characters of the admin username and password from the database. It uses time-based inference to extract data without direct output.
Description
SQL injection vulnerability in shopping/index.php in MyMarket 1.72 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
This Perl script exploits a blind SQL injection vulnerability in MyMarket 1.72 by brute-forcing the length and characters of the admin username and password from the database. It uses time-based inference to extract data without direct output.