CVE-2008-1122

Koobi Pro 5.7 - SQL Injection via Downloads Module categ Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2008-1122. PoCs published by JosS, Cr@zy_King.

AI-analyzed exploit summary This exploit demonstrates multiple SQL injection vulnerabilities in Koobi CMS versions 4.3.0, 4.2.5, and 4.2.4. It provides specific URLs and payloads to extract admin credentials from the database.

Description

SQL injection vulnerability in the downloads module in Koobi Pro 5.7 allows remote attackers to execute arbitrary SQL commands via the categ parameter to index.php. NOTE: it was later reported that this also affects Koobi CMS 4.2.4, 4.2.5, and 4.3.0.

Exploits (2)

exploitdb WORKING POC VERIFIED
by JosS · textwebappsphp
https://www.exploit-db.com/exploits/5447

This exploit demonstrates multiple SQL injection vulnerabilities in Koobi CMS versions 4.3.0, 4.2.5, and 4.2.4. It provides specific URLs and payloads to extract admin credentials from the database.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Koobi CMS 4.3.0, 4.2.5, 4.2.4
No auth needed
Prerequisites: Target running vulnerable Koobi CMS version · Network access to the target
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Cr@zy_King · textwebappsphp
https://www.exploit-db.com/exploits/5198

This is a writeup describing a SQL injection vulnerability in Koobi Pro 5.7. It provides the vulnerable parameter and a sample SQL injection payload but does not include executable exploit code.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Koobi Pro 5.7
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/40903
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5198
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28031
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/490886/100/0/threaded
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5447

Scores

EPSS 0.0100
EPSS Percentile 58.1%

Details

CWE
CWE-89
Status published
Products (1)
dream4/koobi_pro 5.7
Published Mar 03, 2008
Tracked Since Feb 18, 2026