CVE-2008-7058
BandSite CMS 1.1.4 - Cross-Site Request Forgery via Admin Logout Endpoint
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-7058. PoCs published by SirGod.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in BandSite CMS 1.1.4, including arbitrary database download, XSS, and CSRF. The PoC provides direct URLs to trigger these issues without requiring authentication for some vectors.
Description
Cross-site request forgery (CSRF) vulnerability in BandSite CMS 1.1.4 allows remote attackers to hijack the authentication of administrators and force a logout via adminpanel/logout.php.
Exploits (1)
This exploit demonstrates multiple vulnerabilities in BandSite CMS 1.1.4, including arbitrary database download, XSS, and CSRF. The PoC provides direct URLs to trigger these issues without requiring authentication for some vectors.