Record summary

CVE-2008-4161 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.

Description

SQL injection vulnerability in search_inv.php in Assetman 2.5b allows remote attackers to execute arbitrary SQL commands and conduct session fixation attacks via a combination of crafted order and order_by parameters in a search_all action.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBAssetMan 2.5-b - SQL Injection using Session FixationExploitDB exploitby Neo AndersonNot analyzed1 file
ExploitDB

PoC details

References

6