Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-4498. PoCs published by Mr.SQL.
AI-analyzed exploit summary This exploit demonstrates a remote SQL injection vulnerability in PHP Auto's V2.9.1 via the 'catid' parameter in searchresults.php. It extracts user credentials (username, password, email) from the 'tblusers' table using a UNION-based SQL injection.
Description
SQL injection vulnerability in searchresults.php in PHP Autos 2.9.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
Exploits (1)
This exploit demonstrates a remote SQL injection vulnerability in PHP Auto's V2.9.1 via the 'catid' parameter in searchresults.php. It extracts user credentials (username, password, email) from the 'tblusers' table using a UNION-based SQL injection.