CVE-2008-3302
BilboBlog 0.2.1 - Authenticated SQL Injection via admin/delete.php num Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3302. PoCs published by BlackH.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in Bilboblog 2.1, including login bypass, XSS, SQL injection, and full path disclosure. The PoC includes a Ruby script for SQL injection via admin panel.
Description
SQL injection vulnerability in admin/delete.php in BilboBlog 0.2.1, when magic_quotes_gpc is disabled, allows remote authenticated administrators to execute arbitrary SQL commands via the num parameter.
Exploits (1)
This exploit demonstrates multiple vulnerabilities in Bilboblog 2.1, including login bypass, XSS, SQL injection, and full path disclosure. The PoC includes a Ruby script for SQL injection via admin panel.