CVE-2008-4651

Jetbox CMS 2.1 - Authenticated SQL Injection via orderby Parameter or nav_id Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2008-4651. PoCs published by Omer Singer.

AI-analyzed exploit summary The provided text describes a SQL injection vulnerability in Jetbox CMS 2.1, specifically in the 'nav.php' file via the 'nav_id' parameter. It lacks actual exploit code but details the injection point and potential impact.

Description

Multiple SQL injection vulnerabilities in Jetbox CMS 2.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby parameter to admin/cms/images.php and the (2) nav_id parameter in an editrecord action to admin/cms/nav.php.

Exploits (2)

exploitdb WRITEUP VERIFIED
by Omer Singer · textwebappsphp
https://www.exploit-db.com/exploits/32496

The provided text describes a SQL injection vulnerability in Jetbox CMS 2.1, specifically in the 'nav.php' file via the 'nav_id' parameter. It lacks actual exploit code but details the injection point and potential impact.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Jetbox CMS 2.1
No auth needed
Prerequisites: Access to the vulnerable endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Omer Singer · textwebappsphp
https://www.exploit-db.com/exploits/32495

The provided text describes a SQL injection vulnerability in Jetbox CMS 2.1, specifically in the 'orderby' parameter of the admin/cms/images.php endpoint. It lacks executable exploit code but details the vulnerability and potential impact.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Jetbox CMS 2.1
Auth required
Prerequisites: Access to the vulnerable endpoint · Authentication credentials if required
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45986
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31824

Scores

EPSS 0.0080
EPSS Percentile 51.8%

Details

CWE
CWE-89
Status published
Products (1)
jetbox/jetbox_cms 2.1
Published Oct 22, 2008
Tracked Since Feb 18, 2026