Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-2455. PoCs published by Saime.
AI-analyzed exploit summary This exploit demonstrates a blind SQL injection vulnerability in the e107 Plugin BLOG Engine v2.2. The vulnerability exists in the 'rid' parameter of comment.php, allowing an attacker to inject malicious SQL queries. The PoC includes manual test cases and suggests using sqlmap for automated exploitation.
Description
SQL injection vulnerability in comment.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to execute arbitrary SQL commands via the rid parameter.
Exploits (1)
This exploit demonstrates a blind SQL injection vulnerability in the e107 Plugin BLOG Engine v2.2. The vulnerability exists in the 'rid' parameter of comment.php, allowing an attacker to inject malicious SQL queries. The PoC includes manual test cases and suggests using sqlmap for automated exploitation.