CVE-2008-5226
MambAds 1.0 RC1 Beta and 1.0 RC1 - SQL Injection via ma_cat Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5226. PoCs published by Houssamix.
AI-analyzed exploit summary This Perl script exploits a SQL injection vulnerability in the Mambo CMS component mambads (versions 1.0 RC1 Beta and 1.0 RC1) to extract admin usernames and password hashes. It uses a union-based SQL injection to retrieve data from the mos_users table and attempts to crack common MD5 hashes.
Description
SQL injection vulnerability in the MambAds (com_mambads) component 1.0 RC1 Beta and 1.0 RC1 for Mambo allows remote attackers to execute arbitrary SQL commands via the ma_cat parameter in a view action to index.php, a different vector than CVE-2007-5177.
Exploits (1)
This Perl script exploits a SQL injection vulnerability in the Mambo CMS component mambads (versions 1.0 RC1 Beta and 1.0 RC1) to extract admin usernames and password hashes. It uses a union-based SQL injection to retrieve data from the mos_users table and attempts to crack common MD5 hashes.