CVE-2008-4497
Built2Go Real Estate Listings 1.5 - SQL Injection via event_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4497. PoCs published by d3v1l.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Built2Go PHP RealEstate v1.5 via the 'event_id' parameter in 'event_detail.php'. The PoC uses a UNION-based SQLi to extract database version, name, and user information.
Description
SQL injection vulnerability in event_detail.php in Built2Go Real Estate Listings 1.5 allows remote attackers to execute arbitrary SQL commands via the event_id parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Built2Go PHP RealEstate v1.5 via the 'event_id' parameter in 'event_detail.php'. The PoC uses a UNION-based SQLi to extract database version, name, and user information.