CVE-2008-4906
Lyrics (lyrics_menu) plugin 0.42 for e107 - SQL Injection via l_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4906. PoCs published by ZoRLu.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in the e107 Plugin lyrics_menu lyrics_song.php via the l_id parameter. It provides examples for extracting user credentials and database information using UNION-based SQLi.
Description
SQL injection vulnerability in lyrics_song.php in the Lyrics (lyrics_menu) plugin 0.42 for e107 allows remote attackers to execute arbitrary SQL commands via the l_id parameter. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in the e107 Plugin lyrics_menu lyrics_song.php via the l_id parameter. It provides examples for extracting user credentials and database information using UNION-based SQLi.