Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-5195. PoCs published by shinmai.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in SebracCMS, allowing authentication bypass via POST parameter manipulation and information leakage of user credentials via a UNION-based SQLi in a GET parameter.
Description
Multiple SQL injection vulnerabilities in SebracCMS (sbcms) 0.4 allow remote attackers to execute arbitrary SQL commands via (1) the recid parameter to cms/form/read.php, (2) the uname parameter to cms/index.php, and other unspecified vectors.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in SebracCMS, allowing authentication bypass via POST parameter manipulation and information leakage of user credentials via a UNION-based SQLi in a GET parameter.