CVE-2008-3304
BilboBlog 0.2.1 - Exposure of Sensitive Information via Error Message
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3304. PoCs published by BlackH.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in Bilboblog 2.1, including login bypass, XSS, SQL injection, and full path disclosure. The PoC includes a Ruby script for SQL injection via admin panel.
Description
BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to footer.php or (2) a direct request to pagination.php, which reveals the installation path in an error message.
Exploits (1)
This exploit demonstrates multiple vulnerabilities in Bilboblog 2.1, including login bypass, XSS, SQL injection, and full path disclosure. The PoC includes a Ruby script for SQL injection via admin panel.