CVE-2008-4466
Vastal I-Tech Cosmetics Zone - SQL Injection via cat_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4466. PoCs published by Stack.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Vastal I-Tech Cosmetics Zone, allowing an attacker to extract admin credentials via a UNION-based SQLi attack. The PoC provides a direct URL to exploit the vulnerability.
Description
SQL injection vulnerability in view_products_cat.php in Vastal I-Tech Cosmetics Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Vastal I-Tech Cosmetics Zone, allowing an attacker to extract admin credentials via a UNION-based SQLi attack. The PoC provides a direct URL to exploit the vulnerability.