CVE-2008-7040
Yellow Swordfish Simple Forum - SQL Injection via u Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-7040. PoCs published by S@BUN.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Simple Forum, allowing an attacker to extract user credentials from the wp_users table via a crafted URL.
Description
SQL injection vulnerability in ahah/sf-profile.php in the Yellow Swordfish Simple Forum module for Wordpress allows remote attackers to execute arbitrary SQL commands via the u parameter. NOTE: this issue was disclosed by an unreliable researcher, so the details might be incorrect.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in Simple Forum, allowing an attacker to extract user credentials from the wp_users table via a crafted URL.