Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-1513. PoCs published by InATeam.
AI-analyzed exploit summary This PHP script exploits a blind SQL injection vulnerability in Danneo CMS <= 0.5.1 by leveraging the 'Referers statistics' feature. It extracts the admin password hash by timing delays from conditional SQL queries.
Description
SQL injection vulnerability in index.php in Danneo CMS 0.5.1 and earlier, when the Referers statistics option is enabled, allows remote attackers to execute arbitrary SQL commands via the HTTP Referer header.
Exploits (1)
This PHP script exploits a blind SQL injection vulnerability in Danneo CMS <= 0.5.1 by leveraging the 'Referers statistics' feature. It extracts the admin password hash by timing delays from conditional SQL queries.