Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-6779. PoCs published by r45c4l.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in the Sarkilar module for PHP-Nuke. It leverages unsanitized user input in the 'id' parameter to extract sensitive data (passwords, emails, UIDs) from the 'hebuname_authors' table via a UNION-based attack.
Description
SQL injection vulnerability in the Sarkilar module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a showcontent action to modules.php.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in the Sarkilar module for PHP-Nuke. It leverages unsanitized user input in the 'id' parameter to extract sensitive data (passwords, emails, UIDs) from the 'hebuname_authors' table via a UNION-based attack.