CVE-2008-7145
CoronaMatrix phpAddressBook 2.0 - SQL Injection via Username or Password Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-7145. PoCs published by Virangar Security.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in phpAddressBook 2.0 by bypassing authentication via a crafted username input. The payload manipulates the SQL query to return true for any password, allowing unauthorized access.
Description
Multiple SQL injection vulnerabilities in index.php in CoronaMatrix phpAddressBook 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) parameters.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in phpAddressBook 2.0 by bypassing authentication via a crafted username input. The payload manipulates the SQL query to return true for any password, allowing unauthorized access.