Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-4154. PoCs published by Lidloses_Auge.
AI-analyzed exploit summary This PHP script exploits a blind SQL injection vulnerability in WebEdition CMS by brute-forcing the username and password of a specified user ID through time-based inference. It uses ASCII character comparisons to extract data from the database.
Description
SQL injection vulnerability in living-e webEdition CMS allows remote attackers to execute arbitrary SQL commands via the we_objectID parameter.
Exploits (1)
This PHP script exploits a blind SQL injection vulnerability in WebEdition CMS by brute-forcing the username and password of a specified user ID through time-based inference. It uses ASCII character comparisons to extract data from the database.