Exploitation Summary
EIP tracks 1 public exploit for CVE-2008-6652. PoCs published by Cod3rZ.
AI-analyzed exploit summary This exploit targets a blind SQL injection vulnerability in OneCMS 2.5 by leveraging time-based techniques to extract the admin password character by character. It uses the `benchmark` function to infer the correct character based on response time delays.
Description
SQL injection vulnerability in asd.php in OneCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the sitename parameter.
Exploits (1)
This exploit targets a blind SQL injection vulnerability in OneCMS 2.5 by leveraging time-based techniques to extract the admin password character by character. It uses the `benchmark` function to infer the correct character based on response time delays.