CVE-2008-2893
AJ Square aj-hyip - SQL Injection via news.php id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2893. PoCs published by Hussin X.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in HYIP ACME software, allowing an attacker to extract admin credentials via a crafted UNION-based query. The PoC includes a live demo URL and specific payload to dump username and password from the admin table.
Description
SQL injection vulnerability in news.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2008-2532.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in HYIP ACME software, allowing an attacker to extract admin credentials via a crafted UNION-based query. The PoC includes a live demo URL and specific payload to dump username and password from the admin table.