CVE-2008-2890

Online Fantasy Football League <= 0.2.6 - SQL Injection via fflteam_id, league_id, or player_id Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-2890. PoCs published by t0pP8uZz.

AI-analyzed exploit summary This is a writeup detailing SQL injection vulnerabilities in OFFL <= 0.2.6, providing specific exploit URLs to extract admin and user credentials via UNION-based SQLi. No executable code is present.

Description

Multiple SQL injection vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fflteam_id parameter to teams.php, the (2) league_id parameter to leagues.php, and the (3) player_id parameter to players.php.

Exploits (1)

exploitdb WRITEUP VERIFIED
by t0pP8uZz · textwebappsphp
https://www.exploit-db.com/exploits/5889

This is a writeup detailing SQL injection vulnerabilities in OFFL <= 0.2.6, providing specific exploit URLs to extract admin and user credentials via UNION-based SQLi. No executable code is present.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: OFFL <= 0.2.6
No auth needed
Prerequisites: Target running OFFL <= 0.2.6 · Access to vulnerable endpoints (teams.php, leagues.php, players.php)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/29861
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3960
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5889
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30795
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/43259

Scores

EPSS 0.0104
EPSS Percentile 59.5%

Details

CWE
CWE-89
Status published
Products (1)
offl/online_fantasy_football_league 0.2.6
Published Jun 27, 2008
Tracked Since Feb 18, 2026