CVE-2008-3303
BilboBlog 0.2.1 - Unauthenticated Authentication Bypass via Parameter Manipulation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3303. PoCs published by BlackH.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in Bilboblog 2.1, including login bypass, XSS, SQL injection, and full path disclosure. The PoC includes a Ruby script for SQL injection via admin panel.
Description
admin/login.php in BilboBlog 0.2.1, when register_globals is enabled, allows remote attackers to bypass authentication and obtain administrative access via a direct request that sets the login, admin_login, password, and admin_passwd parameters.
Exploits (1)
This exploit demonstrates multiple vulnerabilities in Bilboblog 2.1, including login bypass, XSS, SQL injection, and full path disclosure. The PoC includes a Ruby script for SQL injection via admin panel.