CVE-2008-6328
Butterfly Organizer 2.0.0 and 2.0.1 - SQL Injection via id Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-6328. PoCs published by Osirys, CWH Underground.
AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in Butterfly Organizer 2.0.1 via the 'id' and 'mytable' parameters in the 'view.php' file, allowing arbitrary SQL query execution.
Description
SQL injection vulnerability in view.php in Butterfly Organizer 2.0.0 and 2.0.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (2)
The exploit demonstrates a SQL injection vulnerability in Butterfly Organizer 2.0.1 via the 'id' and 'mytable' parameters in the 'view.php' file, allowing arbitrary SQL query execution.
This exploit demonstrates SQL injection and XSS vulnerabilities in Butterfly Organizer 2.0.0. The SQLi allows arbitrary query execution via the 'id' parameter, while the XSS flaws are present in multiple parameters across different scripts.