Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-3213. PoCs published by Mr.SQL.
AI-analyzed exploit summary This exploit demonstrates a remote SQL injection vulnerability in WebCMS Portal via the 'menu' parameter in index.php. The PoC includes a live demo URL that extracts user credentials (login, password, email) from the 'usuarios' table.
Description
SQL injection vulnerability in secciones/tablon/tablon.php in WebCMS Portal Edition allows remote attackers to execute arbitrary SQL commands via the id parameter to portal/index.php in a tablon action. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates a remote SQL injection vulnerability in WebCMS Portal via the 'menu' parameter in index.php. The PoC includes a live demo URL that extracts user credentials (login, password, email) from the 'usuarios' table.