Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-3752. PoCs published by Hussin X.
AI-analyzed exploit summary The exploit demonstrates an SQL injection vulnerability in YourFreeWorld Ad-Exchange Script by injecting a UNION-based query to extract admin credentials (Username and Password) from the 'adminsettings' table. The payload bypasses authentication by manipulating the 'id' parameter in the 'tr.php' script.
Description
SQL injection vulnerability in tr.php in YourFreeWorld Ad-Exchange Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
The exploit demonstrates an SQL injection vulnerability in YourFreeWorld Ad-Exchange Script by injecting a UNION-based query to extract admin credentials (Username and Password) from the 'adminsettings' table. The payload bypasses authentication by manipulating the 'id' parameter in the 'tr.php' script.