CVE-2008-5954
KTP Computer Customer Database - SQL Injection via lname Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5954. PoCs published by CWH Underground.
AI-analyzed exploit summary The exploit demonstrates a blind SQL injection vulnerability in KTPCCD CMS by manipulating the 'tid' parameter in a URL. It includes proof-of-concept payloads to verify the vulnerability by checking the MySQL version.
Description
SQL injection vulnerability in KTP Computer Customer Database (KTPCCD) CMS, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the lname parameter in a login action to an unspecified component. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
The exploit demonstrates a blind SQL injection vulnerability in KTPCCD CMS by manipulating the 'tid' parameter in a URL. It includes proof-of-concept payloads to verify the vulnerability by checking the MySQL version.