CVE-2008-4744
DXShopCart 4.30mc - SQL Injection via product_detail.php pid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4744. PoCs published by Hussin X.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in DXShopCart 4.30mc by injecting a UNION-based query to extract database information such as user, version, and database name. The attack leverages unsanitized input in the 'pid' parameter of product_detail.php.
Description
SQL injection vulnerability in product_detail.php in DXShopCart 4.30mc allows remote attackers to execute arbitrary SQL commands via the pid parameter.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in DXShopCart 4.30mc by injecting a UNION-based query to extract database information such as user, version, and database name. The attack leverages unsanitized input in the 'pid' parameter of product_detail.php.