CVE-2008-5289
Clean CMS 1.5 - SQL Injection via full_txt.php id Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-5289. PoCs published by ZoRLu, JosS.
AI-analyzed exploit summary This is a writeup detailing blind SQL injection and XSS vulnerabilities in Clean CMS 1.5. It provides example URLs demonstrating the vulnerabilities but does not include executable exploit code.
Description
SQL injection vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (2)
This is a writeup detailing blind SQL injection and XSS vulnerabilities in Clean CMS 1.5. It provides example URLs demonstrating the vulnerabilities but does not include executable exploit code.
This exploit demonstrates a blind SQL injection vulnerability in Clean CMS 1.5 via the 'id' parameter in full_txt.php. It uses multi-threading to brute-force character extraction from the admin credentials stored in the database.