CVE-2008-7118
WeBid 0.5.4 - Unauthenticated Sensitive Information Exposure via Direct Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-7118. PoCs published by InjEctOr5.
AI-analyzed exploit summary This is a writeup detailing multiple vulnerabilities in WeBid v0.5.4, including SQL injection for authentication bypass, arbitrary file editing via CSS manipulation, and exposure of SQL queries through a log file. No executable exploit code is provided.
Description
WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain SQL query logs via a direct request for logs/cron.log.
Exploits (1)
This is a writeup detailing multiple vulnerabilities in WeBid v0.5.4, including SQL injection for authentication bypass, arbitrary file editing via CSS manipulation, and exposure of SQL queries through a log file. No executable exploit code is provided.