CVE-2008-4354
NetArt Media iBoutique 4.0 - SQL Injection via Cat Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4354. PoCs published by r45c4l.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in iBoutique v4.0, allowing an attacker to extract admin credentials (username and password) via crafted HTTP requests. The PoC provides specific URLs to exploit the vulnerability in the 'product&cat' parameter.
Description
SQL injection vulnerability in the products module in NetArt Media iBoutique 4.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter to index.php.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in iBoutique v4.0, allowing an attacker to extract admin credentials (username and password) via crafted HTTP requests. The PoC provides specific URLs to exploit the vulnerability in the 'product&cat' parameter.