Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-2906. PoCs published by Virangar Security.
AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in WebChamado 1.1 via the 'tsk_id' parameter in 'lista_anexos.php'. The crafted query extracts admin credentials (username, password, email) from the 'tbltask_res' table.
Description
SQL injection vulnerability in lista_anexos.php in WebChamado 1.1 allows remote attackers to execute arbitrary SQL commands via the tsk_id parameter.
Exploits (1)
The exploit demonstrates a SQL injection vulnerability in WebChamado 1.1 via the 'tsk_id' parameter in 'lista_anexos.php'. The crafted query extracts admin credentials (username, password, email) from the 'tbltask_res' table.