CVE-2008-3080

myWebland myBloggie 2.1.6 - Cross-Site Request Forgery in admin.php

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-3080. PoCs published by Jesper Jurcenoks.

AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in myBloggie 2.1.6, allowing attackers to extract admin credentials via crafted POST requests. It includes two distinct attack vectors, one targeting user view and another combining SQLi with XSS.

Description

Cross-site request forgery (CSRF) vulnerability in admin.php in myWebland myBloggie 2.1.6 allows remote attackers to perform edit actions as administrators. NOTE: this can be leveraged to execute SQL commands by also exploiting CVE-2007-1899.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jesper Jurcenoks · textwebappsphp
https://www.exploit-db.com/exploits/5975

The exploit demonstrates SQL injection vulnerabilities in myBloggie 2.1.6, allowing attackers to extract admin credentials via crafted POST requests. It includes two distinct attack vectors, one targeting user view and another combining SQLi with XSS.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: myBloggie 2.1.6
No auth needed
Prerequisites: PHP magic_quotes_gpc set to Off · register_globals set to On
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5975
Exploit x_refsource_misc
http://www.netvigilance.com/advisory0040

Scores

EPSS 0.0041
EPSS Percentile 32.8%

Details

CWE
CWE-352
Status published
Products (1)
mywebland/mybloggie 2.1.6
Published Jul 09, 2008
Tracked Since Feb 18, 2026