CVE-2008-6209
Vastal I-Tech Software Zone - SQL Injection via view_product.php cat_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6209. PoCs published by t0pP8uZz.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Software Zone, allowing an attacker to extract admin credentials via a crafted UNION-based SQL query. The PoC targets the 'view_product.php' endpoint with a malicious 'cat_id' parameter.
Description
SQL injection vulnerability in view_product.php in Vastal I-Tech Software Zone allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Software Zone, allowing an attacker to extract admin credentials via a crafted UNION-based SQL query. The PoC targets the 'view_product.php' endpoint with a malicious 'cat_id' parameter.