CVE-2008-7116
WeBid 0.5.4 - SQL Injection via Admin Panel Username Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-7116. PoCs published by InjEctOr5.
AI-analyzed exploit summary This is a writeup detailing multiple vulnerabilities in WeBid v0.5.4, including SQL injection for authentication bypass, arbitrary file editing via CSS manipulation, and exposure of SQL queries through a log file. No executable exploit code is provided.
Description
SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL commands via the username.
Exploits (1)
This is a writeup detailing multiple vulnerabilities in WeBid v0.5.4, including SQL injection for authentication bypass, arbitrary file editing via CSS manipulation, and exposure of SQL queries through a log file. No executable exploit code is provided.