CVE-2008-0301
Mapbender 2.4.4 - SQL Injection via mod_gazetteer_edit.php gaz Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0301. PoCs published by RedTeam Pentesting.
AI-analyzed exploit summary The advisory describes a SQL injection vulnerability in Mapbender 2.4.4, where the 'gaz' parameter in mod_gazetteer_edit.php is not properly sanitized, allowing arbitrary SQL command execution. The proof of concept demonstrates retrieving user credentials from the database.
Description
Multiple SQL injection vulnerabilities in Mapbender 2.4.4 allow remote attackers to execute arbitrary SQL commands via the gaz parameter to mod_gazetteer_edit.php and other unspecified vectors.
Exploits (1)
The advisory describes a SQL injection vulnerability in Mapbender 2.4.4, where the 'gaz' parameter in mod_gazetteer_edit.php is not properly sanitized, allowing arbitrary SQL command execution. The proof of concept demonstrates retrieving user credentials from the database.