Exploitation Summary
EIP tracks 2 public exploits for CVE-2008-3918.
AI-analyzed exploit summary The exploit demonstrates multiple stored and reflected XSS vulnerabilities, as well as a SQL injection flaw in Ovidentia 7.9.4. It includes HTTP request examples with malicious payloads that trigger the vulnerabilities.
Description
SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands via the field parameter in a search action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (2)
The exploit demonstrates multiple stored and reflected XSS vulnerabilities, as well as a SQL injection flaw in Ovidentia 7.9.4. It includes HTTP request examples with malicious payloads that trigger the vulnerabilities.
This exploit demonstrates a SQL injection vulnerability in Ovidentia 6.6.5. The crafted URL injects a UNION-based SQL query to extract user credentials (nickname and password) from the 'bab_users' table.