Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-2608. PoCs published by YEnH4ckEr.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in PHP-AddressBook v4.0.X. It provides multiple SQLi payloads targeting different endpoints (view.php, edit.php, index.php, delete.php) to extract database information such as version and user details.
Description
Multiple SQL injection vulnerabilities in PHP Address Book 4.0.x allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to delete.php or (2) alphabet parameter to index.php. NOTE: the edit.php and view.php vectors are already covered by CVE-2008-2565.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in PHP-AddressBook v4.0.X. It provides multiple SQLi payloads targeting different endpoints (view.php, edit.php, index.php, delete.php) to extract database information such as version and user details.