Record summary

CVE-2008-1398 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.

Description

SQL injection vulnerability in online.php in AuraCMS 2.0 through 2.2.1 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For field (HTTP_X_FORWARDED_FOR environment variable) in an HTTP header.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBAuraCMS 2.2.1 - 'X-Forwarded-For' HTTP Header Blind SQL InjectionExploitDB exploitby NTOS-TeamNot analyzed1 file
ExploitDB

PoC details

References

4