CVE-2008-0388
WP-Forum 1.7.4 - SQL Injection via User Parameter in Showprofile Action
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0388. PoCs published by websec Team.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in WordPress forum plugin by Fredrik Fahlstad version 1.7.4. It allows an attacker to extract user credentials (username, password hash, and email) from the database via a crafted URL.
Description
SQL injection vulnerability in the WP-Forum 1.7.4 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the user parameter in a showprofile action to the default URI.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in WordPress forum plugin by Fredrik Fahlstad version 1.7.4. It allows an attacker to extract user credentials (username, password hash, and email) from the database via a crafted URL.