CVE-2008-4651
Jetbox CMS 2.1 - Authenticated SQL Injection via orderby Parameter or nav_id Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-4651. PoCs published by Omer Singer.
AI-analyzed exploit summary The provided text describes a SQL injection vulnerability in Jetbox CMS 2.1, specifically in the 'nav.php' file via the 'nav_id' parameter. It lacks actual exploit code but details the injection point and potential impact.
Description
Multiple SQL injection vulnerabilities in Jetbox CMS 2.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby parameter to admin/cms/images.php and the (2) nav_id parameter in an editrecord action to admin/cms/nav.php.
Exploits (2)
The provided text describes a SQL injection vulnerability in Jetbox CMS 2.1, specifically in the 'nav.php' file via the 'nav_id' parameter. It lacks actual exploit code but details the injection point and potential impact.
The provided text describes a SQL injection vulnerability in Jetbox CMS 2.1, specifically in the 'orderby' parameter of the admin/cms/images.php endpoint. It lacks executable exploit code but details the vulnerability and potential impact.