CVE-2007-3313

Jasmine CMS 1.0 - SQL Injection via Login Username or News Item Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-3313. PoCs published by Silentz.

AI-analyzed exploit summary This exploit demonstrates SQL injection and remote code execution in Jasmine CMS 1.0 by injecting malicious PHP code into log files and leveraging a vulnerable parameter in plugin_manager.php. It also includes functionality to retrieve admin credentials via SQL injection.

Description

Multiple SQL injection vulnerabilities in Jasmine CMS 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the login_username parameter to login.php or (2) the item parameter to news.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Silentz · phpwebappsphp
https://www.exploit-db.com/exploits/4081

This exploit demonstrates SQL injection and remote code execution in Jasmine CMS 1.0 by injecting malicious PHP code into log files and leveraging a vulnerable parameter in plugin_manager.php. It also includes functionality to retrieve admin credentials via SQL injection.

Classification
Working Poc 100%
Attack Type
Rce | Sqli
Complexity
Moderate
Reliability
Reliable
Target: Jasmine CMS 1.0
No auth needed
Prerequisites: Target must have Jasmine CMS 1.0 installed · Web server must have write permissions to log files · PHP must be configured to allow file inclusion
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (8)

Core 8
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24546
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34936
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2264
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25737
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37069
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/4081
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37068
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34937

Scores

EPSS 0.0175
EPSS Percentile 74.8%

Details

Status published
Products (1)
efstratios_geroulis/jasmine_cms 1.0
Published Jun 21, 2007
Tracked Since Feb 18, 2026