CVE-2008-4144
ACG-ScriptShop E-Gold Script Shop - SQL Injection via cid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4144. PoCs published by Hussin X.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in ACG-ScriptShop, allowing an attacker to extract sensitive information such as usernames and passwords from the database. The exploit uses UNION-based SQL injection to concatenate and retrieve data from tables like 'coders', 'resellers', and 'users'.
Description
SQL injection vulnerability in index.php in ACG-ScriptShop E-Gold Script Shop allows remote attackers to execute arbitrary SQL commands via the cid parameter in a showcat action.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in ACG-ScriptShop, allowing an attacker to extract sensitive information such as usernames and passwords from the database. The exploit uses UNION-based SQL injection to concatenate and retrieve data from tables like 'coders', 'resellers', and 'users'.