CVE-2008-7118

WeBid 0.5.4 - Unauthenticated Sensitive Information Exposure via Direct Request

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-7118. PoCs published by InjEctOr5.

AI-analyzed exploit summary This is a writeup detailing multiple vulnerabilities in WeBid v0.5.4, including SQL injection for authentication bypass, arbitrary file editing via CSS manipulation, and exposure of SQL queries through a log file. No executable exploit code is provided.

Description

WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain SQL query logs via a direct request for logs/cron.log.

Exploits (1)

exploitdb WRITEUP VERIFIED
by InjEctOr5 · textwebappsphp
https://www.exploit-db.com/exploits/6339

This is a writeup detailing multiple vulnerabilities in WeBid v0.5.4, including SQL injection for authentication bypass, arbitrary file editing via CSS manipulation, and exposure of SQL queries through a log file. No executable exploit code is provided.

Classification
Writeup 90%
Attack Type
Sqli | Auth Bypass | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: WeBid v0.5.4
No auth needed
Prerequisites: access to the admin panel URL · knowledge of the target's installation path
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/44820
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6339
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/30945

Scores

EPSS 0.0244
EPSS Percentile 82.2%

Details

CWE
CWE-264
Status published
Products (1)
webidsupport/webid 0.5.4
Published Aug 28, 2009
Tracked Since Feb 18, 2026