Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-4768. PoCs published by ZoRLu.
AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in TLM CMS 3.1 by injecting malicious SQL queries via the 'nom' and 'idnews' parameters. It extracts sensitive user data such as passwords, emails, and usernames from the 'pphp_user' table.
Description
SQL injection vulnerability in TLM CMS 3.1 allows remote attackers to execute arbitrary SQL commands via the nom parameter to a-b-membres.php. NOTE: the goodies.php vector is already covered by CVE-2007-4808. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
The exploit demonstrates SQL injection vulnerabilities in TLM CMS 3.1 by injecting malicious SQL queries via the 'nom' and 'idnews' parameters. It extracts sensitive user data such as passwords, emails, and usernames from the 'pphp_user' table.