Exploitation Summary
EIP tracks 2 public exploits for CVE-2008-3310. PoCs published by DreamTurk.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in PRE SURVEY POLL software, allowing unauthorized extraction of user credentials (usernames and passwords) via crafted URL parameters. The PoC provides direct SQLi payloads targeting the 'catid' parameter.
Description
SQL injection vulnerability in default.asp in Pre Survey Poll allows remote attackers to execute arbitrary SQL commands via the catid parameter.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in PRE SURVEY POLL software, allowing unauthorized extraction of user credentials (usernames and passwords) via crafted URL parameters. The PoC provides direct SQLi payloads targeting the 'catid' parameter.
This exploit demonstrates an SQL injection vulnerability in Pre Survey Generator by injecting a UNION-based query to retrieve user passwords from the database. The attack is performed via the 'catid' parameter in the URL.