CVE-2008-5208
com_datsogallery 1.6 - SQL Injection via User-Agent HTTP Header
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5208. PoCs published by +toxa+.
AI-analyzed exploit summary This exploit targets a blind SQL injection vulnerability in Joomla's com_datsogallery component (version 1.6). It extracts user password hashes and salts by leveraging error-based SQLi via the 'user_rating' parameter in 'sub_votepic.php'.
Description
SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remote attackers to execute arbitrary SQL commands via the User-Agent HTTP header.
Exploits (1)
This exploit targets a blind SQL injection vulnerability in Joomla's com_datsogallery component (version 1.6). It extracts user password hashes and salts by leveraging error-based SQLi via the 'user_rating' parameter in 'sub_votepic.php'.