CVE-2008-4525
ampjuke 0.7.5 - SQL Injection via Special Parameter in Performerid Action
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4525. PoCs published by S_DLA_S.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in AmpJuke 0.7.5 by injecting a UNION-based query to extract user credentials (name and password) from the database. The payload manipulates the 'special' parameter to bypass input sanitization and retrieve sensitive data.
Description
SQL injection vulnerability in index.php in AmpJuke 0.7.5 allows remote attackers to execute arbitrary SQL commands via the special parameter in a performerid action.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in AmpJuke 0.7.5 by injecting a UNION-based query to extract user credentials (name and password) from the database. The payload manipulates the 'special' parameter to bypass input sanitization and retrieve sensitive data.