Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-6875. PoCs published by joseph.giron13.
AI-analyzed exploit summary The exploit demonstrates SQL injection in ASP Product Catalog by injecting a UNION-based query to extract admin credentials. The PoC provides direct URLs with malicious SQL payloads targeting the 'cid' parameter.
Description
SQL injection vulnerability in default.asp in ASP Product Catalog allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2007-5220.
Exploits (1)
The exploit demonstrates SQL injection in ASP Product Catalog by injecting a UNION-based query to extract admin credentials. The PoC provides direct URLs with malicious SQL payloads targeting the 'cid' parameter.