Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-6197. PoCs published by S@BUN.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in KwsPHP v1.3.456, specifically in the 'galerie' module. The PoC uses a UNION-based SQL injection to extract user credentials (pseudo and pass) from the 'users' table.
Description
SQL injection vulnerability in index.php in the galerie module for KwsPHP 1.3.456 allows remote attackers to execute arbitrary SQL commands via the id_gal parameter in a gal action.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in KwsPHP v1.3.456, specifically in the 'galerie' module. The PoC uses a UNION-based SQL injection to extract user credentials (pseudo and pass) from the 'users' table.