CVE-2008-6408
ol'bookmarks 0.7.5 - Remote Code Execution via frame.php framefile Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6408. PoCs published by GoLd_M.
AI-analyzed exploit summary This exploit demonstrates RFI, LFI, and SQL injection vulnerabilities in Ol Bookmarks Manager 0.7.5. The RFI and LFI are due to unsanitized user input in the 'framefile' parameter, while the SQL injection is in the 'id' parameter of index.php.
Description
PHP remote file inclusion vulnerability in frame.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute arbitrary PHP code via a URL in the framefile parameter.
Exploits (1)
This exploit demonstrates RFI, LFI, and SQL injection vulnerabilities in Ol Bookmarks Manager 0.7.5. The RFI and LFI are due to unsanitized user input in the 'framefile' parameter, while the SQL injection is in the 'id' parameter of index.php.