CVE-2008-2521
YABSoft Mega File Hosting Script 1.2 - Authenticated SQL Injection via fid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-2521. PoCs published by TurkishWarriorr.
AI-analyzed exploit summary This exploit demonstrates SQL injection in Mega File Hosting script via the 'fid' parameter in /members.php. It allows unauthorized retrieval of user credentials, admin info, and FTP server details through UNION-based SQLi.
Description
SQL injection vulnerability in members.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote authenticated users to execute arbitrary SQL commands via the fid parameter.
Exploits (1)
This exploit demonstrates SQL injection in Mega File Hosting script via the 'fid' parameter in /members.php. It allows unauthorized retrieval of user credentials, admin info, and FTP server details through UNION-based SQLi.