Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-6029. PoCs published by ~!Dok_tOR!~.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in BuzzyWall <= 1.3.1 by injecting a UNION-based query to extract admin credentials (login and password) from the bw_admin table. The exploit requires magic_quotes_gpc to be disabled.
Description
SQL injection vulnerability in search.php in BuzzyWall 1.3.1 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in BuzzyWall <= 1.3.1 by injecting a UNION-based query to extract admin credentials (login and password) from the bw_admin table. The exploit requires magic_quotes_gpc to be disabled.