CVE-2008-0355
phpecho_cms < 2.0-rc3 - SQL Injection via Forum Module id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0355. PoCs published by Stack.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in PHPEcho CMS 2.0, allowing an attacker to extract username and password from the database via a crafted UNION-based SQL query.
Description
SQL injection vulnerability in index.php in the forum module in PHPEcho CMS, probably 2.0-rc3 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in a section action, a different vector than CVE-2007-2866.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in PHPEcho CMS 2.0, allowing an attacker to extract username and password from the database via a crafted UNION-based SQL query.