CVE-2008-0133
Tribisur < 2.1 - SQL Injection via cat_main.php id Parameter or forum.php cat Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0133. PoCs published by x0kster.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Tribisur <= 2.0 via two endpoints: `cat_main.php` and `forum.php?action=liste`. It extracts the admin password hash by injecting a UNION-based SQL query.
Description
Multiple SQL injection vulnerabilities in Tribisur 2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to cat_main.php and the (2) cat parameter to forum.php in a liste action.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in Tribisur <= 2.0 via two endpoints: `cat_main.php` and `forum.php?action=liste`. It extracts the admin password hash by injecting a UNION-based SQL query.