CVE-2008-6250
Comdev Web Blogger < 4.1.3 - SQL Injection via arcmonth Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6250. PoCs published by K-159.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Comdev Web Blogger <= 4.1.3 via the 'arcmonth' parameter. It allows remote attackers to extract admin and user credentials in plain text when magic_quotes is disabled.
Description
SQL injection vulnerability in Comdev Web Blogger 4.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the arcmonth parameter to a blog page.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Comdev Web Blogger <= 4.1.3 via the 'arcmonth' parameter. It allows remote attackers to extract admin and user credentials in plain text when magic_quotes is disabled.