CVE-2008-6952

MauryCMS <= 0.53.2 - SQL Injection via Rss.php c Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-6952. PoCs published by StAkeR.

AI-analyzed exploit summary This exploit targets MauryCMS <= 0.53.2 by leveraging SQL injection to extract admin credentials and then uploading a malicious PHP shell via an authenticated file upload vulnerability. The script automates the process of retrieving session cookies and uploading the shell.

Description

SQL injection vulnerability in Rss.php in MauryCMS 0.53.2 and earlier allows remote attackers to execute arbitrary SQL commands via the c parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by StAkeR · perlwebappsphp
https://www.exploit-db.com/exploits/7162

This exploit targets MauryCMS <= 0.53.2 by leveraging SQL injection to extract admin credentials and then uploading a malicious PHP shell via an authenticated file upload vulnerability. The script automates the process of retrieving session cookies and uploading the shell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: MauryCMS <= 0.53.2
No auth needed
Prerequisites: Target URL · PHP shell file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/46738
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/32364
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32787
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/7162
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/3216
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/49963

Scores

EPSS 0.0227
EPSS Percentile 80.7%

Details

CWE
CWE-89
Status published
Products (1)
cms.maury91/maurycms 0.53.2
Published Aug 12, 2009
Tracked Since Feb 18, 2026