CVE-2008-5320
e107 < 0.7.13 - Authenticated SQL Injection via ue[] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-5320. PoCs published by girex.
AI-analyzed exploit summary This exploit leverages a blind SQL injection vulnerability in e107 CMS (usersettings.php) by manipulating POST array keys to extract user passwords via time-based benchmark delays. It bypasses PHP security settings like magic_quotes and register_globals.
Description
SQL injection vulnerability in usersettings.php in e107 0.7.13 and earlier allows remote authenticated users to execute arbitrary SQL commands via the ue[] parameter.
Exploits (1)
This exploit leverages a blind SQL injection vulnerability in e107 CMS (usersettings.php) by manipulating POST array keys to extract user passwords via time-based benchmark delays. It bypasses PHP security settings like magic_quotes and register_globals.