CVE-2008-5037
ElkaGroup Image Gallery 1.0 - SQL Injection via view.php cid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5037. PoCs published by G4N0K.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Elkagroup 1.0 by injecting a UNION-based SQL query to extract database information. The PoC URL manipulates the 'cid' parameter to retrieve user data without authentication.
Description
SQL injection vulnerability in view.php in ElkaGroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in Elkagroup 1.0 by injecting a UNION-based SQL query to extract database information. The PoC URL manipulates the 'cid' parameter to retrieve user data without authentication.