CVE-2008-4625
ShiftThis Newsletter - SQL Injection via Newsletter Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4625. PoCs published by r45c4l.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in WordPress stnl_iframe plugin. It allows an attacker to extract user credentials (username, password hash, and email) from the wp_users table via a UNION-based SQL injection.
Description
SQL injection vulnerability in stnl_iframe.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the newsletter parameter, a different vector than CVE-2008-0683.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in WordPress stnl_iframe plugin. It allows an attacker to extract user credentials (username, password hash, and email) from the wp_users table via a UNION-based SQL injection.