Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-3556. PoCs published by Khashayar Fereidani.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Battle.net Clan Script 1.5.2 by injecting malicious SQL queries into the 'page' parameter, allowing unauthorized access to user credentials.
Description
Multiple SQL injection vulnerabilities in index.php in Battle.net Clan Script 1.5.2 allow remote attackers to execute arbitrary SQL commands via the (1) showmember parameter in a members action and the (2) thread parameter in a board action. NOTE: vector 1 might be the same as CVE-2008-2522.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in Battle.net Clan Script 1.5.2 by injecting malicious SQL queries into the 'page' parameter, allowing unauthorized access to user credentials.