CVE-2008-2088
PHP Forge 3.0 beta 2 - SQL Injection via News Module id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2088. PoCs published by JIKO.
AI-analyzed exploit summary This exploit demonstrates a remote SQL injection vulnerability in Forge 3.0 beta. The PoC manipulates the 'id' parameter in the admin.php script to extract sensitive information from the 'membres' table, including usernames and password hashes.
Description
SQL injection vulnerability in admin/news.php in PHP Forge 3.0 beta 2 allows remote attackers to execute arbitrary SQL commands via the id parameter in the news module to admin.php.
Exploits (1)
This exploit demonstrates a remote SQL injection vulnerability in Forge 3.0 beta. The PoC manipulates the 'id' parameter in the admin.php script to extract sensitive information from the 'membres' table, including usernames and password hashes.