CVE-2008-3580
Qsoft K-Links - SQL Injection via id Parameter or PATH_INFO
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3580. PoCs published by Corwin.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in K-Links Directory Platinum. The SQLi allows retrieval of admin credentials, while the XSS is a passive reflected vulnerability.
Description
Multiple SQL injection vulnerabilities in Qsoft K-Links allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to visit.php, or the PATH_INFO to the default URI under (2) report/, (3) addreview/, or (4) refer/.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in K-Links Directory Platinum. The SQLi allows retrieval of admin credentials, while the XSS is a passive reflected vulnerability.