Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-3594. PoCs published by Mr.SQL.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in multiple versions of E-Store Kit software. It leverages a UNION-based SQLi in the 'pid' parameter of viewdetails.php to extract the admin password from the mp2settings table.
Description
SQL injection vulnerability in viewdetails.php in MagicScripts E-Store Kit-1, E-Store Kit-2, E-Store Kit-1 Pro PayPal Edition, and E-Store Kit-2 PayPal Edition allows remote attackers to execute arbitrary SQL commands via the pid parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in multiple versions of E-Store Kit software. It leverages a UNION-based SQLi in the 'pid' parameter of viewdetails.php to extract the admin password from the mp2settings table.