CVE-2008-5088
PHPKB Knowledge Base Software 1.5 Professional - SQL Injection via ID Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-5088. PoCs published by d3v1l, R3d-D3V!L.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in PHPKB Knowledge Base Software v1.5 Professional. It provides proof-of-concept URLs to extract database information, including version, user credentials, and other sensitive data.
Description
Multiple SQL injection vulnerabilities in PHPKB Knowledge Base Software 1.5 Professional allow remote attackers to execute arbitrary SQL commands via the ID parameter to (1) email.php and (2) question.php, a different vector than CVE-2008-1909.
Exploits (2)
This exploit demonstrates SQL injection vulnerabilities in PHPKB Knowledge Base Software v1.5 Professional. It provides proof-of-concept URLs to extract database information, including version, user credentials, and other sensitive data.
This exploit demonstrates SQL injection vulnerabilities in PHPKB Knowledge Base Software v2. It provides two distinct SQLi payloads targeting the 'email.php' and 'comment.php' endpoints to extract database information such as version, user, and database name.