CVE-2008-7080

PHP Classifieds Script - Unauthenticated Sensitive Information Exposure via Direct Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-7080. PoCs published by InjEctOr5.

AI-analyzed exploit summary This is a writeup describing an information leakage vulnerability in PHP Classifieds Script. The exploit involves accessing a backup SQL file to retrieve admin credentials.

Description

Team PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for admin/backup/datadump.sql.

Exploits (1)

exploitdb WRITEUP VERIFIED
by InjEctOr5 · textwebappsphp
https://www.exploit-db.com/exploits/7206

This is a writeup describing an information leakage vulnerability in PHP Classifieds Script. The exploit involves accessing a backup SQL file to retrieve admin credentials.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: PHP Classifieds Script
No auth needed
Prerequisites: Access to the backup SQL file via a predictable path
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32776
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/50153
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/46803
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/7206

Scores

EPSS 0.0759
EPSS Percentile 93.8%

Details

CWE
CWE-264
Status published
Products (1)
phpclassifiedsscript/php_classifieds_script
Published Aug 25, 2009
Tracked Since Feb 18, 2026