Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-6078. PoCs published by StAkeR.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Limbo CMS's private messaging component. The vulnerability allows an attacker to extract sensitive information such as usernames and passwords from the database by manipulating the 'id' parameter in the URL.
Description
SQL injection vulnerability in open.php in the Private Messaging (com_privmsg) component for Limbo CMS allows remote attackers to execute arbitrary SQL commands via the id parameter in a pms action to index.php.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Limbo CMS's private messaging component. The vulnerability allows an attacker to extract sensitive information such as usernames and passwords from the database by manipulating the 'id' parameter in the URL.