CVE-2008-4599
Mosaic Commerce - SQL Injection via category.php cid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4599. PoCs published by Ali Abbasi.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Mosaic Commerce's category.php, allowing an attacker to extract admin credentials via a UNION-based attack. The PoC provides a direct example URL with the payload to retrieve username and password hashes.
Description
SQL injection vulnerability in category.php in Mosaic Commerce allows remote attackers to execute arbitrary SQL commands via the cid parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Mosaic Commerce's category.php, allowing an attacker to extract admin credentials via a UNION-based attack. The PoC provides a direct example URL with the payload to retrieve username and password hashes.