CVE-2008-5841

iGaming CMS < 1.5 - SQL Injection via browse Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2008-5841. PoCs published by Sweet, StAkeR.

AI-analyzed exploit summary The provided text describes SQL injection and blind SQL injection vulnerabilities in iGamingCMS 1.5, including example URLs to exploit these flaws. No actual exploit code is present, only descriptions and proof-of-concept URLs.

Description

Multiple SQL injection vulnerabilities in iGaming 1.5 and earlier allow remote attackers to execute arbitrary SQL commands via the browse parameter to (1) previews.php and (2) reviews.php, and the (3) id parameter to index.php in a viewarticle action.

Exploits (2)

exploitdb WRITEUP VERIFIED
by Sweet · textwebappsphp
https://www.exploit-db.com/exploits/14820

The provided text describes SQL injection and blind SQL injection vulnerabilities in iGamingCMS 1.5, including example URLs to exploit these flaws. No actual exploit code is present, only descriptions and proof-of-concept URLs.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: iGamingCMS 1.5
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by StAkeR · perlwebappsphp
https://www.exploit-db.com/exploits/6540

This Perl script exploits a SQL injection vulnerability in iGaming CMS <= 1.5 by injecting malicious SQL queries into the 'browse' and 'id' parameters of multiple endpoints to extract admin credentials.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: iGaming CMS <= 1.5
No auth needed
Prerequisites: Target URL with vulnerable iGaming CMS installation
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45366
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6540
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31340
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4867

Scores

EPSS 0.0102
EPSS Percentile 58.8%

Details

CWE
CWE-89
Status published
Products (3)
igamingcms/igaming_cms 1.3.1
igamingcms/igaming_cms 1.4.2
igamingcms/igaming_cms < 1.5
Published Jan 05, 2009
Tracked Since Feb 18, 2026