CVE-2008-6720

DeltaScripts PHP Links < 1.3 - SQL Injection via admin_username Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2008-6720. PoCs published by L0n3ly-H34rT, ZoRLu.

AI-analyzed exploit summary This is a technical writeup detailing multiple SQL injection vulnerabilities in DeltaScripts PHP Links 2012. It provides specific endpoints and parameters vulnerable to SQLi, including both GET and POST methods, but does not include functional exploit code.

Description

SQL injection vulnerability in admin/adm_login.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the admin_username parameter (aka the admin field).

Exploits (2)

exploitdb WRITEUP VERIFIED
by L0n3ly-H34rT · textwebappsphp
https://www.exploit-db.com/exploits/37786

This is a technical writeup detailing multiple SQL injection vulnerabilities in DeltaScripts PHP Links 2012. It provides specific endpoints and parameters vulnerable to SQLi, including both GET and POST methods, but does not include functional exploit code.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: DeltaScripts PHP Links 2012
No auth needed
Prerequisites: Access to vulnerable endpoints · Basic knowledge of SQL injection techniques
devstral-2 · analyzed Feb 18, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by ZoRLu · textwebappsphp
https://www.exploit-db.com/exploits/7024

This exploit demonstrates an SQL injection-based authentication bypass in the 'deltascripts phplinks' software. The PoC uses a classic SQLi payload (' or ' 1=1) to bypass the login mechanism, allowing unauthorized access to the admin panel.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: deltascripts phplinks
No auth needed
Prerequisites: access to the login page of the vulnerable application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/32163
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/50392
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/7024

Scores

EPSS 0.0097
EPSS Percentile 57.4%

Details

CWE
CWE-89
Status published
Products (1)
deltascripts/php_links < 1.3
Published Apr 13, 2009
Tracked Since Feb 18, 2026