CVE-2008-4082
Brim 2.0.0 - Authenticated SQL Injection via Tasks Plugin Search Action
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-4082. PoCs published by InjEctOr5.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in Brim 2.0. The SQLi allows unauthorized retrieval of user credentials, while the XSS can execute arbitrary JavaScript in the context of the victim's browser.
Description
SQL injection vulnerability in the Tasks plugin in Brim 2.0.0, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via an arbitrary field in a search action to index.php.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in Brim 2.0. The SQLi allows unauthorized retrieval of user credentials, while the XSS can execute arbitrary JavaScript in the context of the victim's browser.