Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-3720. PoCs published by Khashayar Fereidani.
AI-analyzed exploit summary This exploit demonstrates SQL injection and remote file inclusion (RFI) vulnerabilities in DeeEmm CMS. The SQLi allows unauthorized data extraction from the 'deeemm_users' table, while the RFI enables remote code execution by including a malicious file.
Description
SQL injection vulnerability in index.php in DeeEmm CMS (DMCMS) 0.7.4 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the id vector is already covered by CVE-2007-5679.
Exploits (1)
This exploit demonstrates SQL injection and remote file inclusion (RFI) vulnerabilities in DeeEmm CMS. The SQLi allows unauthorized data extraction from the 'deeemm_users' table, while the RFI enables remote code execution by including a malicious file.