Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-6425. PoCs published by JosS.
AI-analyzed exploit summary This exploit demonstrates a remote SQL injection vulnerability in ComicShout 2.8 via the 'news_id' parameter in news.php. The PoC includes a union-based SQLi payload to extract admin credentials from the 'setup' table.
Description
SQL injection vulnerability in news.php in ComicShout 2.8 allows remote attackers to execute arbitrary SQL commands via the news_id parameter, a different vector than CVE-2008-2456.
Exploits (1)
This exploit demonstrates a remote SQL injection vulnerability in ComicShout 2.8 via the 'news_id' parameter in news.php. The PoC includes a union-based SQLi payload to extract admin credentials from the 'setup' table.