Exploitation Summary
EIP tracks 2 public exploits for CVE-2008-3749. PoCs published by Hussin X, S.W.A.T..
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Banner Management script via the 'id' parameter in 'tr.php'. The payload uses a UNION-based SQLi to extract database information including user, version, and database name.
Description
SQL injection vulnerability in tr.php in YourFreeWorld Banner Management Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in Banner Management script via the 'id' parameter in 'tr.php'. The payload uses a UNION-based SQLi to extract database information including user, version, and database name.
This exploit demonstrates a SQL injection vulnerability in Banner Management Script via the 'id' parameter in tr.php. It extracts admin credentials (username and password) from the 'adminsettings' table using a UNION-based SQLi technique.