CVE-2008-2918
Cartweaver 3.0 - SQL Injection via details.php prodId Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2918. PoCs published by anonymous.
AI-analyzed exploit summary This Perl script exploits a blind SQL injection vulnerability in Cartweaver 3 by brute-forcing the length and characters of admin credentials from the database. It uses time-based inference to extract data without error messages.
Description
SQL injection vulnerability in details.php in Application Dynamics Cartweaver 3.0 allows remote attackers to execute arbitrary SQL commands via the prodId parameter, possibly a related issue to CVE-2006-2046.3.
Exploits (1)
This Perl script exploits a blind SQL injection vulnerability in Cartweaver 3 by brute-forcing the length and characters of admin credentials from the database. It uses time-based inference to extract data without error messages.