CVE-2008-7056
BandSite CMS 1.1.4 - Unauthenticated Database Backup Download via adminpanel/phpmydump.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-7056. PoCs published by SirGod.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in BandSite CMS 1.1.4, including arbitrary database download, XSS, and CSRF. The PoC provides direct URLs to trigger these issues without requiring authentication for some vectors.
Description
BandSite CMS 1.1.4 does not perform access control for adminpanel/phpmydump.php, which allows remote attackers to obtain copies of the database via a direct request.
Exploits (1)
This exploit demonstrates multiple vulnerabilities in BandSite CMS 1.1.4, including arbitrary database download, XSS, and CSRF. The PoC provides direct URLs to trigger these issues without requiring authentication for some vectors.