Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-5847. PoCs published by fuzion.
AI-analyzed exploit summary This is a writeup detailing multiple vulnerabilities in Constructr CMS <= 3.02.5, including directory traversal, source disclosure, arbitrary file creation, and SQL injection. It provides exploit URLs and payloads but lacks executable code.
Description
Constructr CMS 3.02.5 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information by reading the hash column.
Exploits (1)
This is a writeup detailing multiple vulnerabilities in Constructr CMS <= 3.02.5, including directory traversal, source disclosure, arbitrary file creation, and SQL injection. It provides exploit URLs and payloads but lacks executable code.