Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-3774. PoCs published by r45c4l.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Simasy CMS by injecting a UNION-based query to extract user credentials (username, email, and password) from the database. The payload is appended to the 'id' parameter in the URL.
Description
SQL injection vulnerability in index.php in Simasy CMS allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in Simasy CMS by injecting a UNION-based query to extract user credentials (username, email, and password) from the database. The payload is appended to the 'id' parameter in the URL.