CVE-2008-6031
WSN Links 2.22, 2.23, 2.34 - SQL Injection via vote.php id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6031. PoCs published by d3v1l.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in WSN Links 2.22 and 2.23 via the 'id' parameter in vote.php. The PoC uses a UNION-based SQLi to extract database version, name, and user information.
Description
SQL injection vulnerability in vote.php in WSN Links 2.22 and 2.23 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: it was later reported that 2.34 is also vulnerable.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in WSN Links 2.22 and 2.23 via the 'id' parameter in vote.php. The PoC uses a UNION-based SQLi to extract database version, name, and user information.