CVE-2008-6381
bcoos 1.0.13 - Authenticated SQL Injection via cid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6381. PoCs published by CWH Underground.
AI-analyzed exploit summary This Perl script exploits a SQL injection vulnerability in bcoos 1.0.13 by injecting a malicious query into the 'cid' parameter of the 'viewcat.php' module. It retrieves usernames and passwords from the 'bcoos_users' table.
Description
SQL injection vulnerability in modules/adresses/viewcat.php in bcoos 1.0.13, and possibly earlier, allows remote authenticated users with Addresses module permissions to execute arbitrary SQL commands via the cid parameter.
Exploits (1)
This Perl script exploits a SQL injection vulnerability in bcoos 1.0.13 by injecting a malicious query into the 'cid' parameter of the 'viewcat.php' module. It retrieves usernames and passwords from the 'bcoos_users' table.