CVE-2008-5707

Iltaweb Alisveris Sistemi - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-5707. PoCs published by tRoot.

AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in ASP Indir Iltaweb Alisveris Sistemi by injecting a UNION-based SQL query to extract data from the 'users' table. The vulnerability arises from insufficient input sanitization in the 'catno' parameter.

Description

SQL injection vulnerability in urunler.asp in Iltaweb Alisveris Sistemi allows remote attackers to execute arbitrary SQL commands via the catno parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by tRoot · textwebappsasp
https://www.exploit-db.com/exploits/32485

This exploit demonstrates an SQL injection vulnerability in ASP Indir Iltaweb Alisveris Sistemi by injecting a UNION-based SQL query to extract data from the 'users' table. The vulnerability arises from insufficient input sanitization in the 'catno' parameter.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: ASP Indir Iltaweb Alisveris Sistemi
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/497279/100/0/threaded
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31740

Scores

EPSS 0.0037
EPSS Percentile 59.0%

Details

CWE
CWE-89
Status published
Products (1)
aspindir/iltaweb_alisveris_sistemi _nil_
Published Dec 24, 2008
Tracked Since Feb 18, 2026