CVE-2008-0821

OSI Codes Inc. PHP Live! 3.2.2 - SQL Injection via questid Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2008-0821. PoCs published by skys, Xar.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in PHP Live! software, allowing an attacker to extract admin credentials from the database via a crafted URL. The PoC uses a UNION-based SQLi to retrieve login and password hashes from either the chat_asp or chat_admin tables.

Description

SQL injection vulnerability in admin/traffic/knowledge_searchm.php in OSI Codes Inc. PHP Live! 3.2.2 allows remote attackers to execute arbitrary SQL commands via the questid parameter in an expand_question action.

Exploits (2)

exploitdb WORKING POC VERIFIED
by skys · textwebappsphp
https://www.exploit-db.com/exploits/9254

This exploit demonstrates a SQL injection vulnerability in PHP Live! software, allowing an attacker to extract admin credentials from the database via a crafted URL. The PoC uses a UNION-based SQLi to retrieve login and password hashes from either the chat_asp or chat_admin tables.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: PHP Live! (OSI Codes Inc.)
No auth needed
Prerequisites: Access to the vulnerable PHP Live! installation
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Xar · textwebappsphp
https://www.exploit-db.com/exploits/5125

This exploit demonstrates a SQL injection vulnerability in PHP Live! software, allowing an attacker to extract admin credentials (login and password hashes) via a crafted URL. The payload uses a UNION-based SQLi to concatenate and retrieve sensitive data from the 'chat_admin' table.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: PHP Live! (OSI Codes Inc.)
No auth needed
Prerequisites: Access to the vulnerable PHP Live! installation
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/27807
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5125

Scores

EPSS 0.0045
EPSS Percentile 63.8%

Details

CWE
CWE-89
Status published
Products (1)
osi_codes_inc./phplive 3.2.2
Published Feb 19, 2008
Tracked Since Feb 18, 2026