Exploitation Summary
EIP tracks 2 public exploits for CVE-2008-3954. PoCs published by r45c4l.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Alstrasoft Forum via the 'catid' parameter in the 'forum_catview' menu. It allows an attacker to extract admin and user credentials by manipulating the SQL query through a UNION-based attack.
Description
SQL injection vulnerability in index.php in AlstraSoft Forum Pay Per Post Exchange allows remote attackers to execute arbitrary SQL commands via the cat parameter in a showcat action.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in Alstrasoft Forum via the 'catid' parameter in the 'forum_catview' menu. It allows an attacker to extract admin and user credentials by manipulating the SQL query through a UNION-based attack.
This exploit demonstrates a SQL injection vulnerability in Altrasoft Forum, allowing an attacker to extract admin and user credentials via crafted SQL queries in the 'cat' parameter.