CVE-2008-1909
PHPKB Knowledge Base 1.5 and 2.0 - SQL Injection via ID Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-1909. PoCs published by parad0x.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in PHPKB Knowledge Base Software via the 'ID' parameter in comment.php. The example shows a UNION-based SQLi to extract database information, user credentials, and OS version.
Description
SQL injection vulnerability in comment.php in PHP Knowledge Base (PHPKB) 1.5 and 2.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in PHPKB Knowledge Base Software via the 'ID' parameter in comment.php. The example shows a UNION-based SQLi to extract database information, user credentials, and OS version.
The exploit demonstrates SQL injection vulnerabilities in PHPKB Knowledge Base Software v2 via the 'ID' parameter in 'email.php' and 'comment.php'. It includes specific payloads to extract database version, user, and OS information.