CVE-2008-4080
Stash 1.0.3 - SQL Injection via Username or Download Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4080. PoCs published by Khashayar Fereidani.
AI-analyzed exploit summary This exploit details SQL injection and authentication bypass vulnerabilities in Stash v1.0.3. It provides manual steps for admin bypass and remote file disclosure via SQLi, but lacks executable code.
Description
SQL injection vulnerability in Stash 1.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the (1) username parameter to admin/library/authenticate.php and the (2) download parameter to downloadmp3.php. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit details SQL injection and authentication bypass vulnerabilities in Stash v1.0.3. It provides manual steps for admin bypass and remote file disclosure via SQLi, but lacks executable code.