CVE-2008-1506
peel < 3.0 - Exposure of Sensitive Information via phpinfo.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-1506. PoCs published by Charles Fol.
AI-analyzed exploit summary This exploit targets multiple vulnerabilities in PEEL CMS, including SQL injection, blind SQL injection, and authentication bypass to extract admin hashes and upload a malicious file. It demonstrates a multi-stage attack chain to achieve remote code execution.
Description
PEEL, possibly 3.x and earlier, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.
Exploits (1)
This exploit targets multiple vulnerabilities in PEEL CMS, including SQL injection, blind SQL injection, and authentication bypass to extract admin hashes and upload a malicious file. It demonstrates a multi-stage attack chain to achieve remote code execution.