CVE-2008-1496

PEEL - SQL Injection via Email Parameter or Timestamp Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-1496. PoCs published by Charles Fol.

AI-analyzed exploit summary This exploit targets multiple vulnerabilities in PEEL CMS, including SQL injection, blind SQL injection, and authentication bypass to extract admin hashes and upload a malicious file. It demonstrates a multi-stage attack chain to achieve remote code execution.

Description

Multiple SQL injection vulnerabilities in PEEL, possibly 3.x and earlier, allow remote attackers to execute arbitrary SQL commands via the (1) email parameter to (a) membre.php, and the (2) timestamp parameter to (b) the details action in achat/historique_commandes.php and (c) the facture action in factures/facture_html.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Charles Fol · phpwebappsphp
https://www.exploit-db.com/exploits/5281

This exploit targets multiple vulnerabilities in PEEL CMS, including SQL injection, blind SQL injection, and authentication bypass to extract admin hashes and upload a malicious file. It demonstrates a multi-stage attack chain to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: PEEL CMS (various versions including PREMIUM, POWERSELL, INTEGRALE, PROFESSIONNELLE)
No auth needed
Prerequisites: Access to the target PEEL CMS installation · Network connectivity to the target
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41341
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29466
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5281
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28346
Exploit x_refsource_misc
http://realn.free.fr/releases/70207
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41353

Scores

EPSS 0.0116
EPSS Percentile 63.0%

Details

CWE
CWE-89
Status published
Products (3)
peel/peel 1.0b
peel/peel 2.6
peel/peel 2.7
Published Mar 25, 2008
Tracked Since Feb 18, 2026