CVE-2008-7080
PHP Classifieds Script - Unauthenticated Sensitive Information Exposure via Direct Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-7080. PoCs published by InjEctOr5.
AI-analyzed exploit summary This is a writeup describing an information leakage vulnerability in PHP Classifieds Script. The exploit involves accessing a backup SQL file to retrieve admin credentials.
Description
Team PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain database credentials via a direct request for admin/backup/datadump.sql.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by InjEctOr5 · textwebappsphp
https://www.exploit-db.com/exploits/7206
This is a writeup describing an information leakage vulnerability in PHP Classifieds Script. The exploit involves accessing a backup SQL file to retrieve admin credentials.
Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target:
PHP Classifieds Script
No auth needed
Prerequisites:
Access to the backup SQL file via a predictable path
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (4)
Core 4
Core References
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/32776
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/50153
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/46803
Exploit, Third Party Advisory exploit
x_refsource_exploit-db
https://www.exploit-db.com/exploits/7206
Scores
EPSS
0.0759
EPSS Percentile
93.8%
Details
CWE
CWE-264
Status
published
Products (1)
phpclassifiedsscript/php_classifieds_script
Published
Aug 25, 2009
Tracked Since
Feb 18, 2026