CVE-2008-4621
ZeeScripts Zeeproperty - SQL Injection via bannerclick.php adid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4621. PoCs published by Hussin X.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in zeeproperty's bannerclick.php script, allowing an attacker to extract admin credentials via a crafted UNION-based SQL query. The PoC includes a functional exploit URL that concatenates the admin username and password from the database.
Description
SQL injection vulnerability in bannerclick.php in ZeeScripts Zeeproperty allows remote attackers to execute arbitrary SQL commands via the adid parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in zeeproperty's bannerclick.php script, allowing an attacker to extract admin credentials via a crafted UNION-based SQL query. The PoC includes a functional exploit URL that concatenates the admin username and password from the database.