Exploitation Summary
EIP tracks 2 public exploits for CVE-2008-5655. PoCs published by ZoRLu, G4N0K.
AI-analyzed exploit summary This exploit demonstrates a SQL injection-based authentication bypass in MyioSoft EasyBookMarker. By injecting a tautology (' or ' 1=1) into the username field, an attacker can bypass authentication without valid credentials.
Description
Multiple SQL injection vulnerabilities in MyioSoft EasyBookMarker 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) delete_folder and (2) delete_link parameters to unspecified vectors, possibly to (a) plugins/bookmarker/bookmarker_backend.php or (b) ajaxp.php, different vectors than CVE-2008-5654. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (2)
This exploit demonstrates a SQL injection-based authentication bypass in MyioSoft EasyBookMarker. By injecting a tautology (' or ' 1=1) into the username field, an attacker can bypass authentication without valid credentials.
This exploit demonstrates a SQL injection vulnerability in Myiosoft EasyBookMarker v4. The attack leverages a UNION-based SQLi in the 'Parent' parameter to extract database version and user information.