CVE-2008-4754
Scripts for Sites Ez Forum - SQL Injection via Forum Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4754. PoCs published by Hurley.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in SFS Forum's forum.php by manipulating the 'forum' parameter to extract user credentials (password, username, email) via a UNION-based attack. The PoC includes a live demo URL and a crafted payload.
Description
SQL injection vulnerability in forum.php in Scripts for Sites (SFS) Ez Forum allows remote attackers to execute arbitrary SQL commands via the forum parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in SFS Forum's forum.php by manipulating the 'forum' parameter to extract user credentials (password, username, email) via a UNION-based attack. The PoC includes a live demo URL and a crafted payload.