CVE-2008-4884
YourFreeWorld Classifieds Hosting Script - SQL Injection via tr.php id Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-4884. PoCs published by Hussin X.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Classifieds Hosting software via the 'id' parameter in 'tr.php'. The payload extracts admin credentials (Username and Password) from the 'adminsettings' table using a UNION-based SQL injection technique.
Description
SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Hosting Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in Classifieds Hosting software via the 'id' parameter in 'tr.php'. The payload extracts admin credentials (Username and Password) from the 'adminsettings' table using a UNION-based SQL injection technique.
This exploit demonstrates a SQL injection vulnerability in Banner Management script via the 'id' parameter. The PoC uses a UNION-based SQLi to extract database information (user, version, database name).