Record summary

CVE-2008-2521 has a selected CVSS score of 6.5; EIP currently links 1 catalogued exploit.

Description

SQL injection vulnerability in members.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote authenticated users to execute arbitrary SQL commands via the fid parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBMega File Hosting Script 1.2 - 'fid' SQL InjectionExploitDB exploitby TurkishWarriorrNot analyzed1 file
ExploitDB

PoC details

References

5