CVE-2008-5992
Jetik Emlak Sistem A 2.0 - SQL Injection via KayitNo Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5992. PoCs published by ZoRLu.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Jetik Emlak ESA 2.0 via the 'KayitNo' parameter in 'diger.php' and 'sayfalar.php'. It uses a UNION-based SQLi to extract database information such as user, database name, and version.
Description
Multiple SQL injection vulnerabilities in Jetik Emlak Sistem A (ESA) 2.0 allow remote attackers to execute arbitrary SQL commands via the KayitNo parameter to (1) diger.php and (2) sayfalar.php.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Jetik Emlak ESA 2.0 via the 'KayitNo' parameter in 'diger.php' and 'sayfalar.php'. It uses a UNION-based SQLi to extract database information such as user, database name, and version.