Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-3672.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Classified Ads software via the 'cid' parameter in browsecats.php. The PoC extracts admin credentials by leveraging a UNION-based SQLi attack.
Description
SQL injection vulnerability in showcategory.php in PozScripts Classified Ads allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2008-3673. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Classified Ads software via the 'cid' parameter in browsecats.php. The PoC extracts admin credentials by leveraging a UNION-based SQLi attack.