CVE-2008-4157
Vastal I-Tech phpVID 1.1 and 1.2.3 - SQL Injection via groups.php cat Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-4157. PoCs published by 3spi0n, r45c4l.
AI-analyzed exploit summary This document describes multiple vulnerabilities in PhpVID Script, including SQL injection, XSS, and CRLF injection. It provides example URLs to exploit these vulnerabilities but does not include executable exploit code.
Description
SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 1.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter, a different vector than CVE-2007-3610. NOTE: it was later reported that 1.2.3 is also affected.
Exploits (2)
This document describes multiple vulnerabilities in PhpVID Script, including SQL injection, XSS, and CRLF injection. It provides example URLs to exploit these vulnerabilities but does not include executable exploit code.
The exploit demonstrates a blind SQL injection vulnerability in the 'cat' parameter of 'groups.php' and a cross-site scripting (XSS) vulnerability in 'search_results.php' for phpVID 1.1. It includes proof-of-concept URLs to trigger these vulnerabilities.