CVE-2008-6805

Mic_Blog 0.0.3 - SQL Injection via cat user or site Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-6805. PoCs published by StAkeR.

AI-analyzed exploit summary This exploit targets Mic_blog v0.0.3, demonstrating SQL injection and privilege escalation vulnerabilities. It extracts user credentials via SQLi and can add a new administrator account.

Description

Multiple SQL injection vulnerabilities in Mic_Blog 0.0.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to category.php, the (2) user parameter to login.php, and the (3) site parameter to register.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by StAkeR · phpwebappsphp
https://www.exploit-db.com/exploits/6764

This exploit targets Mic_blog v0.0.3, demonstrating SQL injection and privilege escalation vulnerabilities. It extracts user credentials via SQLi and can add a new administrator account.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: Mic_blog v0.0.3
No auth needed
Prerequisites: Network access to the target application · Knowledge of the table prefix and user ID
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/49188
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/31787
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/49187
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/45932
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6764
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32310
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/49186

Scores

EPSS 0.0112
EPSS Percentile 61.8%

Details

CWE
CWE-89
Status published
Products (1)
micgr/mic_blog 0.0.3
Published May 11, 2009
Tracked Since Feb 18, 2026