CVE-2008-4090
PHP Coupon Script 4.0 - SQL Injection via id Parameter in addtocart Action
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4090. PoCs published by Hussin X.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Coupon Script 4.0 via the 'id' parameter in the 'addtocart' page. The PoC uses a UNION-based SQL injection to extract database information, user credentials, and version details.
Description
SQL injection vulnerability in index.php in PHP Coupon Script 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in an addtocart action, a different vector than CVE-2007-2672.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Coupon Script 4.0 via the 'id' parameter in the 'addtocart' page. The PoC uses a UNION-based SQL injection to extract database information, user credentials, and version details.