CVE-2008-6204
SuperNET Shop < 1.0 - SQL Injection via id, kulad, sifre, username, or password Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6204. PoCs published by U238.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in SuperNET Shop v1.0, allowing unauthorized access to admin credentials via a crafted union-based SQL query. It also includes an authentication bypass method using SQL injection in the login form.
Description
Multiple SQL injection vulnerabilities in SuperNET Shop 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to secure/admin/guncelle.asp, (2) kulad and sifre parameters to secure/admin/giris.asp, and (3) username and password to secure/admin/default.asp.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in SuperNET Shop v1.0, allowing unauthorized access to admin credentials via a crafted union-based SQL query. It also includes an authentication bypass method using SQL injection in the login form.