CVE-2008-3669
ZeeScripts Reviews Opinions Rating Posting Engine Web-Site PHP Script - SQL Injection via ItemID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3669. PoCs published by Mr.SQL.
AI-analyzed exploit summary This is a functional SQL injection exploit for ZeeReviews, targeting the 'ItemID' parameter in 'comments.php'. The exploit leverages a UNION-based SQLi to extract username and password from the 'zr_users' table.
Description
SQL injection vulnerability in comments.php in ZeeScripts Reviews Opinions Rating Posting Engine Web-Site PHP Script (aka ZeeReviews) allows remote attackers to execute arbitrary SQL commands via the ItemID parameter.
Exploits (1)
This is a functional SQL injection exploit for ZeeReviews, targeting the 'ItemID' parameter in 'comments.php'. The exploit leverages a UNION-based SQLi to extract username and password from the 'zr_users' table.