CVE-2008-6725
CMScout 2.06 - Authenticated SQL Injection via id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6725. PoCs published by SirGod.
AI-analyzed exploit summary The exploit demonstrates SQL injection and local file inclusion vulnerabilities in CMScout 2.06. It provides specific payloads for authenticated users to extract credentials and read arbitrary files via path traversal.
Description
Multiple SQL injection vulnerabilities in CMScout 2.06 allow remote authenticated users to execute arbitrary SQL commands via the id parameter to (1) index.php in a mythings page (mythings.php) and (2) the users page in admin.php.
Exploits (1)
The exploit demonstrates SQL injection and local file inclusion vulnerabilities in CMScout 2.06. It provides specific payloads for authenticated users to extract credentials and read arbitrary files via path traversal.