CVE-2008-3588
phsblog 0.1.1 - SQL Injection via eid, cid, or urltitle Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-3588. PoCs published by cOndemned.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in phsBlog v0.1.1, allowing unauthorized extraction of user credentials via UNION-based SQLi in multiple endpoints. The PoC includes payloads for both Magic Quotes enabled and disabled scenarios.
Description
Multiple SQL injection vulnerabilities in phsBlog 0.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to comments.php, (2) cid parameter to index.php, and the (3) urltitle parameter to entries.php.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in phsBlog v0.1.1, allowing unauthorized extraction of user credentials via UNION-based SQLi in multiple endpoints. The PoC includes payloads for both Magic Quotes enabled and disabled scenarios.