CVE-2008-4889
deV!L'z Clanportal <= 1.4.9.6 - SQL Injection via Users Parameter in Addbuddy Operation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4889. PoCs published by anonymous.
AI-analyzed exploit summary This exploit targets a SQL injection vulnerability in deV!L`z Clanportal, specifically in the 'addbuddy' functionality. It performs a blind SQL injection to extract the administrator password character by character using binary search.
Description
SQL injection vulnerability in index.php in deV!L'z Clanportal (DZCP) 1.4.9.6 and earlier allows remote attackers to execute arbitrary SQL commands via the users parameter in an addbuddy operation in a buddys action.
Exploits (1)
This exploit targets a SQL injection vulnerability in deV!L`z Clanportal, specifically in the 'addbuddy' functionality. It performs a blind SQL injection to extract the administrator password character by character using binary search.