CVE-2008-2902
AlstraSoft AskMe Pro < 2.1 - SQL Injection via Profile ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2902. PoCs published by t0pP8uZz.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in AlstraSoft AskMe Pro <= 2.1, allowing remote attackers to extract plaintext usernames and passwords from the database via crafted UNION-based SQL queries.
Description
SQL injection vulnerability in profile.php in AlstraSoft AskMe Pro 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: The que_id parameter to forum_answer.php is already covered by CVE-2007-4085.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in AlstraSoft AskMe Pro <= 2.1, allowing remote attackers to extract plaintext usernames and passwords from the database via crafted UNION-based SQL queries.