CVE-2008-6409

ol'bookmarks manager 0.7.5 - SQL Injection via id Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2008-6409. PoCs published by GoLd_M, Mehmet Ince, ThE TiGeR.

AI-analyzed exploit summary This exploit demonstrates RFI, LFI, and SQL injection vulnerabilities in Ol Bookmarks Manager 0.7.5. The RFI and LFI are due to unsanitized user input in the 'framefile' parameter, while the SQL injection is in the 'id' parameter of index.php.

Description

SQL injection vulnerability in index.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute arbitrary SQL commands via the id parameter in a brain action.

Exploits (3)

exploitdb WORKING POC VERIFIED
by GoLd_M · textwebappsphp
https://www.exploit-db.com/exploits/6547

This exploit demonstrates RFI, LFI, and SQL injection vulnerabilities in Ol Bookmarks Manager 0.7.5. The RFI and LFI are due to unsanitized user input in the 'framefile' parameter, while the SQL injection is in the 'id' parameter of index.php.

Classification
Working Poc 90%
Attack Type
Sqli | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Ol Bookmarks Manager 0.7.5
No auth needed
Prerequisites: Network access to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Mehmet Ince · textwebappsphp
https://www.exploit-db.com/exploits/3964

This exploit demonstrates a SQL injection vulnerability in Ol Bookmarks Manager 0.7.4, allowing remote attackers to extract sensitive information (e.g., passwords, logins) from the database via a crafted URL parameter.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Ol Bookmarks Manager 0.7.4
No auth needed
Prerequisites: Target application must be accessible · SQL injection vulnerability must be unpatched
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by ThE TiGeR · textwebappsphp
https://www.exploit-db.com/exploits/3962

This exploit demonstrates a Remote File Inclusion (RFI) vulnerability in Olbookmarks <= 0.7.4. The vulnerability allows an attacker to include arbitrary remote files via the 'root' parameter in multiple PHP scripts, potentially leading to remote code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Olbookmarks <= 0.7.4
No auth needed
Prerequisites: Network access to the target application · Ability to host a malicious file on a remote server
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45368
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6547

Scores

EPSS 0.0094
EPSS Percentile 56.1%

Details

CWE
CWE-89
Status published
Products (1)
brian_wilson/ol\'bookmarks 0.7.5
Published Mar 06, 2009
Tracked Since Feb 18, 2026