CVE-2008-4521
World of Warcraft tracker infusion module 2.0 - SQL Injection via INFO_RAID_ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4521. PoCs published by boom3rang.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in PHP-Fusion's raidtracker_panel module. The exploit uses a UNION-based SQL injection to extract user credentials from the fusion_users table.
Description
SQL injection vulnerability in thisraidprogress.php in the World of Warcraft tracker infusion (raidtracker_panel) module 2.0 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the INFO_RAID_ID parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in PHP-Fusion's raidtracker_panel module. The exploit uses a UNION-based SQL injection to extract user credentials from the fusion_users table.