CVE-2008-4709
Pilot Group eTraining - SQL Injection via News Read ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4709. PoCs published by S.W.A.T..
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Pilot Online Training Solution, allowing an attacker to extract admin credentials (login and MD5 password) from the 'students' table. The PoC provides a direct URL manipulation technique to achieve this.
Description
SQL injection vulnerability in news_read.php in Pilot Group (PG) eTraining allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Pilot Online Training Solution, allowing an attacker to extract admin credentials (login and MD5 password) from the 'students' table. The PoC provides a direct URL manipulation technique to achieve this.