CVE-2008-3129
Catviz 0.4 beta 1 - SQL Injection via Foreign Key Value or Webpage Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3129. PoCs published by anonymous.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Catviz 0.4.0 beta1. It provides specific URLs and payloads to extract sensitive information, such as usernames and passwords, from the database.
Description
Multiple SQL injection vulnerabilities in index.php in Catviz 0.4 beta 1 allow remote attackers to execute arbitrary SQL commands via the (1) foreign_key_value parameter in the news page and (2) webpage parameter in the webpage_multi_edit form.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in Catviz 0.4.0 beta1. It provides specific URLs and payloads to extract sensitive information, such as usernames and passwords, from the database.