Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-2858.
AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in WebChamado 1.1 via the 'tsk_id' parameter in lista_anexos.php, allowing an attacker to extract admin credentials from the database. The payload uses a UNION-based SQLi to concatenate and retrieve username, password, and email fields.
Description
SQL injection vulnerability in index.php in WebChamado 1.1 allows remote attackers to execute arbitrary SQL commands via the eml parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
The exploit demonstrates a SQL injection vulnerability in WebChamado 1.1 via the 'tsk_id' parameter in lista_anexos.php, allowing an attacker to extract admin credentials from the database. The payload uses a UNION-based SQLi to concatenate and retrieve username, password, and email fields.