CVE-2008-0447
Foojan WMS PHP Weblog 1.0 - SQL Injection via Story Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-0447. PoCs published by Khashayar Fereidani.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Foojan WMS 1.0, allowing an attacker to extract admin credentials via a crafted URL parameter. The PoC includes a specific SQL query to retrieve usernames and passwords from the 'authors' table.
Description
SQL injection vulnerability in index.php in Foojan WMS PHP Weblog 1.0 allows remote attackers to execute arbitrary SQL commands via the story parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Foojan WMS 1.0, allowing an attacker to extract admin credentials via a crafted URL parameter. The PoC includes a specific SQL query to retrieve usernames and passwords from the 'authors' table.