CVE-2008-6798
Pre Projects Pre Real Estate Listings - SQL Injection via Username or Password Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6798. PoCs published by BackDoor.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass via SQL injection in the login form and an unrestricted file upload vulnerability in the profile editing functionality of Pre Real Estate Listings. The SQL injection allows bypassing authentication, and the file upload can be abused to achieve remote code execution.
Description
Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to execute arbitrary SQL commands via (1) the us parameter (aka the Username field) or (2) the ps parameter (aka the Password field).
Exploits (1)
This exploit demonstrates an authentication bypass via SQL injection in the login form and an unrestricted file upload vulnerability in the profile editing functionality of Pre Real Estate Listings. The SQL injection allows bypassing authentication, and the file upload can be abused to achieve remote code execution.