CVE-2007-4808

TLM CMS 3.2 - SQL Injection via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-4808. PoCs published by k1tk4t.

AI-analyzed exploit summary This exploit demonstrates multiple SQL injection vulnerabilities in TLM CMS v3.2, allowing unauthorized access to user credentials via crafted HTTP requests. The PoC includes specific URLs with injected SQL queries targeting different files within the application.

Description

Multiple SQL injection vulnerabilities in TLM CMS 3.2 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to news.php in a lirenews action, (2) the idnews parameter to goodies.php in a lire action, (3) the id parameter to file.php in a voir action, (4) the ID parameter to affichage.php, (5) the id_sal parameter to mod_forum/afficher.php, or (6) the id_sujet parameter to mod_forum/messages.php. NOTE: it was later reported that goodies.php and affichage.php scripts are reachable through index.php, and 1.1 is also affected. NOTE: it was later reported that the goodies.php vector also affects 3.1.

Exploits (1)

exploitdb WORKING POC VERIFIED
by k1tk4t · textwebappsphp
https://www.exploit-db.com/exploits/4376

This exploit demonstrates multiple SQL injection vulnerabilities in TLM CMS v3.2, allowing unauthorized access to user credentials via crafted HTTP requests. The PoC includes specific URLs with injected SQL queries targeting different files within the application.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: TLM CMS v3.2
No auth needed
Prerequisites: Target application must be running TLM CMS v3.2 · Magic quotes must be disabled for some vectors
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (14)

Core 14
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/42204
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/36536
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26752
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/25602
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/3137
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37001
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37002
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37005
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/4376
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37003
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/29049
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37004
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37006

Scores

EPSS 0.0360
EPSS Percentile 88.0%

Details

CWE
CWE-89
Status published
Products (2)
tlm_cms/tlm_cms 1.1
tlm_cms/tlm_cms 3.2
Published Sep 11, 2007
Tracked Since Feb 18, 2026