Exploitation Summary
EIP tracks 2 public exploits for CVE-2008-5978. PoCs published by Pouya_Server, Charalambous Glafkos.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Ocean12 Mailing List Manager Gold, including direct database download (info_leak), SQL injection, and XSS. The PoC provides specific URLs to trigger these vulnerabilities without requiring authentication.
Description
Multiple SQL injection vulnerabilities in Ocean12 Mailing List Manager Gold allow remote attackers to execute arbitrary SQL commands via the Email parameter to (1) default.asp and (2) s_edit.asp.
Exploits (2)
The exploit demonstrates multiple vulnerabilities in Ocean12 Mailing List Manager Gold, including direct database download (info_leak), SQL injection, and XSS. The PoC provides specific URLs to trigger these vulnerabilities without requiring authentication.
The provided text describes an SQL injection vulnerability in Ocean12 Mailing List Manager Gold 2.04, where the 'Email' parameter in a specific URL is not properly sanitized. This allows attackers to inject malicious SQL queries, potentially compromising the application or underlying database.