CVE-2008-7120
hot_links_sql-php < 3 - SQL Injection via news.php Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-7120. PoCs published by r45c4l.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Hot Links SQL-PHP by injecting a UNION-based query to extract database version, name, and user information. The PoC leverages unsanitized input in the 'id' parameter to execute arbitrary SQL commands.
Description
SQL injection vulnerability in Mr. CGI Guy Hot Links SQL-PHP 3 and earlier allows remote attackers to execute arbitrary SQL commands via the news.php parameter.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in Hot Links SQL-PHP by injecting a UNION-based query to extract database version, name, and user information. The PoC leverages unsanitized input in the 'id' parameter to execute arbitrary SQL commands.