CVE-2008-3058
Octeth Oempro 3.5.5.1 - SQL Injection via FormValue_Email or FormValue_SearchKeywords Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3058. PoCs published by security curmudgeon.
AI-analyzed exploit summary The provided text describes a SQL injection vulnerability in Octeth Oempro 3.5.5.1, where unsanitized user input in the 'Email' field can be exploited to manipulate SQL queries. It includes an example payload but lacks executable code.
Description
Multiple SQL injection vulnerabilities in Octeth Oempro 3.5.5.1, and possibly other versions before 4, allow remote attackers to execute arbitrary SQL commands via the FormValue_Email parameter (aka Email field) to index.php in (1) member/, (2) client/, or (3) admin/; or (4) the FormValue_SearchKeywords parameter to client/campaign_track.php.
Exploits (1)
The provided text describes a SQL injection vulnerability in Octeth Oempro 3.5.5.1, where unsanitized user input in the 'Email' field can be exploited to manipulate SQL queries. It includes an example payload but lacks executable code.