CVE-2008-6028
University of Queensland Library Fez <2.0 RC1 - SQL Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6028. PoCs published by d3v1l.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Fez software versions 1.3 and 2.0 RC1 via the 'list.php' script. The PoC uses a UNION-based SQL injection to extract database version, name, and user information.
Description
SQL injection vulnerability in list.php in University of Queensland Library Fez 1.3 and 2.0 RC1 allows remote attackers to execute arbitrary SQL commands via the parent_id parameter in a subject action.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Fez software versions 1.3 and 2.0 RC1 via the 'list.php' script. The PoC uses a UNION-based SQL injection to extract database version, name, and user information.