CVE-2008-4150
Diesel Joke Site - SQL Injection via picture_category.php id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4150. PoCs published by SarBoT511.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in the 'picture_category.php' script of a DieselScripts.com application. The PoC uses a UNION-based SQLi to extract admin credentials (aid and apass) from the database.
Description
SQL injection vulnerability in picture_category.php in Diesel Joke Site allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2006-3763.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in the 'picture_category.php' script of a DieselScripts.com application. The PoC uses a UNION-based SQLi to extract admin credentials (aid and apass) from the database.