CVE-2008-4778
Koobi CMS 4.3.0 - SQL Injection via Gallery Module galid Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-4778. PoCs published by JosS, S@BUN.
AI-analyzed exploit summary This exploit demonstrates multiple SQL injection vulnerabilities in Koobi CMS versions 4.3.0, 4.2.5, and 4.2.4. It provides specific URLs and payloads to extract admin credentials from the database.
Description
SQL injection vulnerability in the gallery module in Koobi CMS 4.3.0 allows remote attackers to execute arbitrary SQL commands via the galid parameter in a showimages action.
Exploits (2)
This exploit demonstrates multiple SQL injection vulnerabilities in Koobi CMS versions 4.3.0, 4.2.5, and 4.2.4. It provides specific URLs and payloads to extract admin credentials from the database.
This exploit demonstrates a SQL injection vulnerability in Koobi Pro V6.25 via the 'galid' parameter, allowing an attacker to extract user credentials (email and password) from the 'kpro_user' table.