CVE-2008-4786
e107 easyshop_plugin - SQL Injection via category_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4786. PoCs published by StAkeR.
AI-analyzed exploit summary This Perl script exploits a blind SQL injection vulnerability in the EasyShop plugin for e107 CMS. It iterates through possible ASCII characters to extract the admin user's password hash by checking for differences in the response content.
Description
SQL injection vulnerability in easyshop.php in the EasyShop plugin for e107 allows remote attackers to execute arbitrary SQL commands via the category_id parameter.
Exploits (1)
This Perl script exploits a blind SQL injection vulnerability in the EasyShop plugin for e107 CMS. It iterates through possible ASCII characters to extract the admin user's password hash by checking for differences in the response content.