CVE-2008-6622
webbdomian post_card < 1.02 - SQL Injection via choosecard.php catid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6622. PoCs published by Hussin X.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in the 'post Card' application versions 1.01 and 1.02. The vulnerability allows an attacker to extract admin credentials by manipulating the 'catid' parameter in the URL.
Description
SQL injection vulnerability in choosecard.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02, 1.01, and earlier allows remote attackers to execute arbitrary SQL commands via the catid parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in the 'post Card' application versions 1.01 and 1.02. The vulnerability allows an attacker to extract admin credentials by manipulating the 'catid' parameter in the URL.