CVE-2008-0428

bloofoxCMS 0.3 - SQL Injection via Username or Password Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-0428. PoCs published by BugReport.IR.

AI-analyzed exploit summary This writeup describes SQL injection and source code disclosure vulnerabilities in Bloofox CMS 0.3. The SQLi allows authentication bypass via crafted input, while the source disclosure enables arbitrary file reads via directory traversal.

Description

Multiple SQL injection vulnerabilities in the login function in system/class_permissions.php in bloofoxCMS 0.3 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to admin/index.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by BugReport.IR · textwebappsphp
https://www.exploit-db.com/exploits/4945

This writeup describes SQL injection and source code disclosure vulnerabilities in Bloofox CMS 0.3. The SQLi allows authentication bypass via crafted input, while the source disclosure enables arbitrary file reads via directory traversal.

Classification
Writeup 90%
Attack Type
Sqli | Info Leak | Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Bloofox CMS 0.3
No auth needed
Prerequisites: Magic quotes disabled · Access to login page and file.php
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0218
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/39794
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/28415
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/486714/100/0/threaded
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/4945
Exploit mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=120093005310107&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27361
Exploit x_refsource_misc
http://bugreport.ir/?/27

Scores

EPSS 0.0168
EPSS Percentile 73.9%

Details

CWE
CWE-89
Status published
Products (1)
bloofoxcms/bloofoxcms 0.3
Published Jan 23, 2008
Tracked Since Feb 18, 2026