CVE-2008-6781
Sites for Scripts Gaming Directory - SQL Injection via cat_id Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-6781. PoCs published by Hurley, BeyazKurt.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in SFS EZ Gaming Directory via the 'cat_id' parameter in directory.php. The PoC includes a live demo URL showing how to extract user credentials (password and email) from the database.
Description
SQL injection vulnerability in directory.php in Sites for Scripts (SFS) Gaming Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in SFS EZ Gaming Directory via the 'cat_id' parameter in directory.php. The PoC includes a live demo URL showing how to extract user credentials (password and email) from the database.
This is a writeup describing an SQL injection vulnerability in SFS Gaming Directory. It provides an example exploit URL but does not include functional exploit code.