CVE-2008-4883
YourFreeWorld Blog Blaster Script - SQL Injection via tr.php id Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-4883. PoCs published by Hussin X.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Blog Blaster, allowing an attacker to extract admin credentials via a crafted UNION-based SQL query. The PoC includes a live demo URL and the exact injection string.
Description
SQL injection vulnerability in tr.php in YourFreeWorld Blog Blaster Script allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in Blog Blaster, allowing an attacker to extract admin credentials via a crafted UNION-based SQL query. The PoC includes a live demo URL and the exact injection string.
This exploit demonstrates a SQL injection vulnerability in Banner Management script via the 'id' parameter in tr.php. The PoC uses a UNION-based SQLi to extract database information including user, version, and database name.