Exploitation Summary
EIP tracks 2 public exploits for CVE-2008-5841. PoCs published by Sweet, StAkeR.
AI-analyzed exploit summary The provided text describes SQL injection and blind SQL injection vulnerabilities in iGamingCMS 1.5, including example URLs to exploit these flaws. No actual exploit code is present, only descriptions and proof-of-concept URLs.
Description
Multiple SQL injection vulnerabilities in iGaming 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the browse parameter to (1) previews.php and (2) reviews.php, and the (3) id parameter to index.php in a viewarticle action.
Exploits (2)
The provided text describes SQL injection and blind SQL injection vulnerabilities in iGamingCMS 1.5, including example URLs to exploit these flaws. No actual exploit code is present, only descriptions and proof-of-concept URLs.
This Perl script exploits a SQL injection vulnerability in iGaming CMS <= 1.5 by injecting malicious SQL queries into the 'browse' and 'id' parameters of multiple endpoints to extract admin credentials.