CVE-2008-3200
avlc_forum - SQL Injection via id Parameter in affich_message Action
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3200. PoCs published by CWH Underground.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Avlc Forum's vlc_forum.php file. The PoC leverages a UNION-based SQL injection to extract user data from the mysql.user table by manipulating the 'id' parameter.
Description
SQL injection vulnerability in vlc_forum.php in Avlc Forum as of 20080715 allows remote attackers to execute arbitrary SQL commands via the id parameter in an affich_message action.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Avlc Forum's vlc_forum.php file. The PoC leverages a UNION-based SQL injection to extract user data from the mysql.user table by manipulating the 'id' parameter.