CVE-2008-4356

Kasseler CMS 1.1.0 and 1.2.0 - SQL Injection via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-4356. PoCs published by ~!Dok_tOR!~.

AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Kasseler CMS versions 1.1.0 and 1.2.4. It includes multiple crafted URLs targeting different modules to extract user credentials and other sensitive database information.

Description

Multiple SQL injection vulnerabilities in Kasseler CMS 1.1.0 and 1.2.0 allow remote attackers to execute arbitrary SQL commands via (1) the nid parameter to index.php in a View action to the News module; (2) the vid parameter to index.php in a Result action to the Voting module; (3) the fid parameter to index.php in a ShowForum action to the Forum module; (4) the tid parameter to index.php in a ShowTopic action to the Forum module; (5) the uname parameter to index.php in a UserInfo action to the Account module; or (6) the module parameter to index.php, probably related to the TopSites module.

Exploits (1)

exploitdb WORKING POC VERIFIED
by ~!Dok_tOR!~ · textwebappsphp
https://www.exploit-db.com/exploits/6460

This exploit demonstrates SQL injection vulnerabilities in Kasseler CMS versions 1.1.0 and 1.2.4. It includes multiple crafted URLs targeting different modules to extract user credentials and other sensitive database information.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Kasseler CMS 1.1.0, 1.2.4
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45120
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31170
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6460
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/31862

Scores

EPSS 0.0097
EPSS Percentile 57.2%

Details

CWE
CWE-89
Status published
Products (2)
kasseler-cms/kasseler_cms 1.1.0
kasseler-cms/kasseler_cms 1.2.0 lite
Published Sep 30, 2008
Tracked Since Feb 18, 2026