CVE-2008-6409
ol'bookmarks manager 0.7.5 - SQL Injection via id Parameter
Title source: llmExploitation Summary
EIP tracks 3 public exploits for CVE-2008-6409. PoCs published by GoLd_M, Mehmet Ince, ThE TiGeR.
AI-analyzed exploit summary This exploit demonstrates RFI, LFI, and SQL injection vulnerabilities in Ol Bookmarks Manager 0.7.5. The RFI and LFI are due to unsanitized user input in the 'framefile' parameter, while the SQL injection is in the 'id' parameter of index.php.
Description
SQL injection vulnerability in index.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute arbitrary SQL commands via the id parameter in a brain action.
Exploits (3)
This exploit demonstrates RFI, LFI, and SQL injection vulnerabilities in Ol Bookmarks Manager 0.7.5. The RFI and LFI are due to unsanitized user input in the 'framefile' parameter, while the SQL injection is in the 'id' parameter of index.php.
This exploit demonstrates a SQL injection vulnerability in Ol Bookmarks Manager 0.7.4, allowing remote attackers to extract sensitive information (e.g., passwords, logins) from the database via a crafted URL parameter.
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Olbookmarks <= 0.7.4. The vulnerability allows an attacker to include arbitrary remote files via the 'root' parameter in multiple PHP scripts, potentially leading to remote code execution.