Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-3554. PoCs published by james.
AI-analyzed exploit summary This exploit targets a SQL injection vulnerability in Discuz! 6.0.1 by injecting a malicious query into the search parameter to retrieve user passwords. It sends a crafted POST request to the target server to extract password hashes from the database.
Description
SQL injection vulnerability in index.php in Discuz! 6.0.1 allows remote attackers to execute arbitrary SQL commands via the searchid parameter in a search action.
Exploits (1)
This exploit targets a SQL injection vulnerability in Discuz! 6.0.1 by injecting a malicious query into the search parameter to retrieve user passwords. It sends a crafted POST request to the target server to extract password hashes from the database.