CVE-2008-6656
Open Auto Classifieds 1.4.3b - SQL Injection via Listings ID Parameter or Login Username Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6656. PoCs published by InjEctOr5.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Open Auto Classifieds v1.4.3b, allowing an attacker to extract user credentials via a crafted URL and bypass authentication using a simple SQL payload.
Description
Multiple SQL injection vulnerabilities in Open Auto Classifieds 1.4.3b allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to listings.php and (2) the username field to login.php.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Open Auto Classifieds v1.4.3b, allowing an attacker to extract user credentials via a crafted URL and bypass authentication using a simple SQL payload.