Exploitation Summary
EIP tracks 2 public exploits for CVE-2008-3491. PoCs published by Mr.SQL.
AI-analyzed exploit summary This exploit demonstrates a remote SQL injection vulnerability in the iTGP script's go.php action parameter. It allows an attacker to extract username and password from the itgp_moderator table via UNION-based SQL injection.
Description
SQL injection vulnerability in go.php in Scripts24 iPost 1.0.1 and iTGP 1.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter in a report action.
Exploits (2)
This exploit demonstrates a remote SQL injection vulnerability in the iTGP script's go.php action parameter. It allows an attacker to extract username and password from the itgp_moderator table via UNION-based SQL injection.
This exploit demonstrates a remote SQL injection vulnerability in iPOST's go.php action parameter. It allows an attacker to extract sensitive information such as usernames and passwords from the database.