CVE-2008-4156
CustomCms Gaming Portal 4.0 - SQL Injection via print.php id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4156. PoCs published by ~!Dok_tOR!~.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in CCMS Gaming Portal 4.0 via the 'id' parameter in print.php. It leverages a UNION-based attack to extract admin credentials when magic_quotes_gpc is disabled.
Description
SQL injection vulnerability in print.php in CustomCms (CCMS) Gaming Portal 4.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in CCMS Gaming Portal 4.0 via the 'id' parameter in print.php. It leverages a UNION-based attack to extract admin credentials when magic_quotes_gpc is disabled.