CVE-2008-6247
Scripts For Sites EZ Top Sites - SQL Injection via topsite.php ts Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6247. PoCs published by Stack.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in SFS EZ Top Sites, allowing an attacker to extract user passwords via a UNION-based SQLi attack. The PoC provides a crafted URL that retrieves password hashes from the 'users' table.
Description
SQL injection vulnerability in topsite.php in Scripts For Sites (SFS) EZ Top Sites allows remote attackers to execute arbitrary SQL commands via the ts parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in SFS EZ Top Sites, allowing an attacker to extract user passwords via a UNION-based SQLi attack. The PoC provides a crafted URL that retrieves password hashes from the 'users' table.