Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-4706. PoCs published by elusiven.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Vbgooglemap Hotspot Edition 1.0.3. The vulnerability allows an attacker to extract sensitive user information, including passwords and salts, by manipulating the 'mapid' parameter in a UNION-based SQL injection attack.
Description
SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote attackers to execute arbitrary SQL commands via the mapid parameter in a showdetails action to (1) vbgooglemaphse.php and (2) mapa.php.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Vbgooglemap Hotspot Edition 1.0.3. The vulnerability allows an attacker to extract sensitive user information, including passwords and salts, by manipulating the 'mapid' parameter in a UNION-based SQL injection attack.