CVE-2008-5064
H&H WebSoccer 2.80 - SQL Injection via liga.php id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5064. PoCs published by d3v1l.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in H&H Solutions WebSoccer 2.80 by injecting a UNION-based query to extract database version, name, and user information. The payload is appended to the 'id' parameter in the 'liga.php' script.
Description
SQL injection vulnerability in liga.php in H&H WebSoccer 2.80 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in H&H Solutions WebSoccer 2.80 by injecting a UNION-based query to extract database version, name, and user information. The payload is appended to the 'id' parameter in the 'liga.php' script.