CVE-2008-3561

Powergap Shopsystem - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-3561. PoCs published by Rohit Bansal.

AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in POWERGAP Shopsystem, where unsanitized user input in the 'ag' parameter of s03.php can be exploited to manipulate SQL queries. No actual exploit code is included, only a description and a sample URL.

Description

SQL injection vulnerability in s03.php in Powergap Shopsystem, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the ag parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Rohit Bansal · textwebappsphp
https://www.exploit-db.com/exploits/32179

The provided text describes an SQL injection vulnerability in POWERGAP Shopsystem, where unsanitized user input in the 'ag' parameter of s03.php can be exploited to manipulate SQL queries. No actual exploit code is included, only a description and a sample URL.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: POWERGAP Shopsystem
No auth needed
Prerequisites: Access to the vulnerable endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/30558
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/44270
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31382

Scores

EPSS 0.0091
EPSS Percentile 55.5%

Details

CWE
CWE-89
Status published
Products (1)
powergap/shopsystem
Published Aug 10, 2008
Tracked Since Feb 18, 2026