CVE-2008-6421
Social Site Generator 2.0 - Remote Code Execution via social_game_play.php Path Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-6421. PoCs published by DeAr Ev!L, vBmad.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Social Site Generator v2. It provides specific URLs to extract admin credentials (admin_id and password) from the web_admin table via UNION-based SQLi.
Description
PHP remote file inclusion vulnerability in social_game_play.php in Social Site Generator (SSG) 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
Exploits (2)
This exploit demonstrates SQL injection vulnerabilities in Social Site Generator v2. It provides specific URLs to extract admin credentials (admin_id and password) from the web_admin table via UNION-based SQLi.
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Social Site Generator v2. The vulnerable parameter 'path' in 'social_game_play.php' allows an attacker to include and execute remote malicious scripts.