CVE-2008-4355
Powie PSCRIPT Forum <= 1.30 - SQL Injection via showprofil.php id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4355. PoCs published by tmh.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Powie's PHP Forum v1.30 via the 'id' parameter in showprofil.php. It allows an attacker to extract user credentials and email addresses through UNION-based SQL injection.
Description
SQL injection vulnerability in showprofil.php in Powie PSCRIPT Forum (aka PHP Forum or pForum) 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Powie's PHP Forum v1.30 via the 'id' parameter in showprofil.php. It allows an attacker to extract user credentials and email addresses through UNION-based SQL injection.