Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-4043. PoCs published by security fears team.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in the 'ajhyip manager script' via the 'comment.php' endpoint. The PoC uses a UNION-based SQLi to extract username and password from the 'members' table.
Description
Multiple SQL injection vulnerabilities in AJ Square AJ HYIP Acme allow remote attackers to execute arbitrary SQL commands via the artid parameter to (1) acme/article/comment.php and (2) prime/article/comment.php.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in the 'ajhyip manager script' via the 'comment.php' endpoint. The PoC uses a UNION-based SQLi to extract username and password from the 'members' table.