CVE-2008-2860
AJSquare AJ Auction Pro 2.0 - SQL Injection via category.php cate_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2860. PoCs published by Hussin X.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Auction Web 2.0, allowing an attacker to extract admin credentials via a crafted UNION-based query. The PoC targets the 'cate_id' parameter in 'category.php' to dump usernames and passwords from the 'admin' table.
Description
SQL injection vulnerability in category.php in AJSquare AJ Auction Pro web 2.0 allows remote attackers to execute arbitrary SQL commands via the cate_id parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Auction Web 2.0, allowing an attacker to extract admin credentials via a crafted UNION-based query. The PoC targets the 'cate_id' parameter in 'category.php' to dump usernames and passwords from the 'admin' table.