CVE-2008-6477

Mumbojumbo Op4 - SQL Injection

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-6477. PoCs published by Lidloses_Auge.

AI-analyzed exploit summary This PHP script exploits a blind SQL injection vulnerability in Mumbo Jumbo Media's OP4 CMS by brute-forcing the admin username and password hash via time-based inference. It iterates through possible ASCII values to extract data from the database.

Description

SQL injection vulnerability in Mumbo Jumbo Media OP4 allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Lidloses_Auge · phpwebappsphp
https://www.exploit-db.com/exploits/5440

This PHP script exploits a blind SQL injection vulnerability in Mumbo Jumbo Media's OP4 CMS by brute-forcing the admin username and password hash via time-based inference. It iterates through possible ASCII values to extract data from the database.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Mumbo Jumbo Media OP4 CMS
No auth needed
Prerequisites: Target URL with vulnerable 'id' parameter · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28763
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1211/references
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5440
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/49303

Scores

EPSS 0.0097
EPSS Percentile 57.4%

Details

CWE
CWE-89
Status published
Products (1)
mumbojumbo/op4
Published Mar 16, 2009
Tracked Since Feb 18, 2026