CVE-2008-4902
Article Publisher Pro 1.5 - SQL Injection via Userid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4902. PoCs published by Stack.
AI-analyzed exploit summary This is a functional blind SQL injection exploit for Article Publisher Pro, leveraging time-based or boolean-based techniques to extract data such as database version or user information. The script automates the extraction by measuring response lengths to infer true/false conditions.
Description
SQL injection vulnerability in contact_author.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary SQL commands via the userid parameter.
Exploits (1)
This is a functional blind SQL injection exploit for Article Publisher Pro, leveraging time-based or boolean-based techniques to extract data such as database version or user information. The script automates the extraction by measuring response lengths to infer true/false conditions.