CVE-2008-4161
Assetman 2.5b - SQL Injection via search_inv.php order and order_by Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4161. PoCs published by Neo Anderson.
AI-analyzed exploit summary This is a writeup describing a session fixation attack via SQL injection in AssetMan v2.5-b. The vulnerability allows an attacker to manipulate cookies through a crafted HTTP request to the 'search_inv.php' file using the 'order_by' parameter.
Description
SQL injection vulnerability in search_inv.php in Assetman 2.5b allows remote attackers to execute arbitrary SQL commands and conduct session fixation attacks via a combination of crafted order and order_by parameters in a search_all action.
Exploits (1)
This is a writeup describing a session fixation attack via SQL injection in AssetMan v2.5-b. The vulnerability allows an attacker to manipulate cookies through a crafted HTTP request to the 'search_inv.php' file using the 'order_by' parameter.