CVE-2008-6210
dream4 Koobi 4.4 and 5.4 - SQL Injection via img_id Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2008-6210. PoCs published by BILGE_KAGAN, S@BUN.
AI-analyzed exploit summary This exploit leverages a SQL injection vulnerability in Koobi Pro v6.1 via the 'img_id' parameter to extract user credentials (email and password) from the 'kpro6_user' table. The attack is straightforward and relies on a UNION-based SQLi technique.
Description
SQL injection vulnerability in index.php in dream4 Koobi 4.4 and 5.4 allows remote attackers to execute arbitrary SQL commands via the img_id parameter in the gallerypic page.
Exploits (2)
This exploit leverages a SQL injection vulnerability in Koobi Pro v6.1 via the 'img_id' parameter to extract user credentials (email and password) from the 'kpro6_user' table. The attack is straightforward and relies on a UNION-based SQLi technique.
This exploit demonstrates SQL injection in Koobi CMS versions 4.4 and 5.4 via the 'img_id' parameter, allowing unauthorized extraction of user credentials (email and password) from the database.