CVE-2008-4885
YourFreeWorld Scrolling Text Ads Script - SQL Injection via id Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-4885. PoCs published by Hussin X.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Short Url & Url Tracker software, allowing an attacker to extract admin credentials via a crafted UNION-based SQL query. The PoC includes a live demo URL and a generic Dork for finding vulnerable instances.
Description
SQL injection vulnerability in tr1.php in YourFreeWorld Scrolling Text Ads Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in Short Url & Url Tracker software, allowing an attacker to extract admin credentials via a crafted UNION-based SQL query. The PoC includes a live demo URL and a generic Dork for finding vulnerable instances.
This is a functional SQL injection exploit for CVE-2008-4885, targeting the 'Scrolling Text Ads' script. The exploit leverages a UNION-based SQL injection to extract admin credentials from the 'adminsettings' table.