Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-4711. PoCs published by ~!Dok_tOR!~.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Joovili <= 3.0, allowing attackers to extract user and admin credentials via UNION-based SQLi in multiple endpoints. The PoC requires magic_quotes_gpc to be disabled.
Description
SQL injection vulnerability in Joovili 3.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter to (1) view.blog.php, (2) view.event.php, (3) view.group.php, (4) view.music.php, (5) view.picture.php, and (6) view.video.php.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in Joovili <= 3.0, allowing attackers to extract user and admin credentials via UNION-based SQLi in multiple endpoints. The PoC requires magic_quotes_gpc to be disabled.