CVE-2008-6242
Scripts For Sites EZ e-store - SQL Injection via SearchResults.php where Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-6242. PoCs published by Salvatore Fresta, ZoRLu.
AI-analyzed exploit summary This is a writeup describing a SQL injection vulnerability in E-Store, a commercial PHP e-commerce application. The vulnerability exists in the 'where' parameter of SearchResults.php, allowing attackers to inject malicious SQL queries.
Description
SQL injection vulnerability in SearchResults.php in Scripts For Sites (SFS) EZ e-store allows remote attackers to execute arbitrary SQL commands via the where parameter.
Exploits (2)
This is a writeup describing a SQL injection vulnerability in E-Store, a commercial PHP e-commerce application. The vulnerability exists in the 'where' parameter of SearchResults.php, allowing attackers to inject malicious SQL queries.
This exploit demonstrates a SQL injection vulnerability in SFS EZ WEBSTORE's SearchResults.php. The PoC injects a UNION-based SQL query to extract database information such as user, database name, and version.