Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-3780. PoCs published by Mr.SQL.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in the Five Star Review script. The SQL injection allows unauthorized extraction of user and admin credentials via crafted `item_id` parameters, while the XSS vulnerability is triggered through the search functionality.
Description
SQL injection vulnerability in recommend.php in Five Star Review Script allows remote attackers to execute arbitrary SQL commands via the item_id parameter.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in the Five Star Review script. The SQL injection allows unauthorized extraction of user and admin credentials via crafted `item_id` parameters, while the XSS vulnerability is triggered through the search functionality.