CVE-2008-4423
Ovidentia 6.6.5 - SQL Injection via Item Parameter in Contact Modify Action
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-4423. PoCs published by LiquidWorm, Khashayar Fereidani.
AI-analyzed exploit summary The exploit demonstrates multiple stored and reflected XSS vulnerabilities, as well as an SQL injection flaw in Ovidentia 7.9.4. It includes HTTP request examples with malicious payloads that trigger the vulnerabilities.
Description
SQL injection vulnerability in index.php in Ovidentia 6.6.5 allows remote attackers to execute arbitrary SQL commands via the item parameter in a contact modify action.
Exploits (2)
The exploit demonstrates multiple stored and reflected XSS vulnerabilities, as well as an SQL injection flaw in Ovidentia 7.9.4. It includes HTTP request examples with malicious payloads that trigger the vulnerabilities.
This exploit demonstrates a SQL injection vulnerability in Ovidentia 6.6.5, allowing an attacker to extract user credentials (nickname and password) from the database. The exploit requires authentication as a simple user before execution.