CVE-2008-5192
Philboard 1.14 and 1.2 - SQL Injection via forum.asp forumid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5192. PoCs published by Bl@ckbe@rD.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in philboard v1.14. The SQLi uses a blind injection technique, while the XSS exploit leverages a simple script tag to steal cookies.
Description
SQL injection vulnerability in forum.asp in W1L3D4 Philboard 1.14 and 1.2 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. NOTE: this might overlap CVE-2008-2334, CVE-2008-1939, CVE-2007-2641, or CVE-2007-0920.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in philboard v1.14. The SQLi uses a blind injection technique, while the XSS exploit leverages a simple script tag to steal cookies.