CVE-2008-2834
Scientific Image DataBase 0.41 - SQL Injection via projects.php id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2834. PoCs published by t0pP8uZz.
AI-analyzed exploit summary This exploit leverages a blind SQL injection vulnerability in Scientific Image DataBase to extract the admin password via substring brute-forcing. It authenticates as a guest user and iteratively checks ASCII values to reconstruct the password.
Description
SQL injection vulnerability in projects.php in Scientific Image DataBase 0.41 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
This exploit leverages a blind SQL injection vulnerability in Scientific Image DataBase to extract the admin password via substring brute-forcing. It authenticates as a guest user and iteratively checks ASCII values to reconstruct the password.