Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-5267. PoCs published by CWH Underground.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in the Experts application version 1.0.0. The vulnerability allows an attacker to extract administrator credentials by manipulating the 'question_id' parameter in the 'answer.php' script.
Description
SQL injection vulnerability in answer.php in Experts 1.0.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the question_id parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in the Experts application version 1.0.0. The vulnerability allows an attacker to extract administrator credentials by manipulating the 'question_id' parameter in the 'answer.php' script.