Exploit catalog results

Showing 6 PoCs on this page

ExploitDB

IBSng B1.34(T96) - 'str' Cross-Site Scripting

ExploitDB exploitPublished 2011-11-01
Not analyzedUnlinked1 file
ExploitDB

Pars CMS - 'RP' Multiple SQL Injections

ExploitDB exploitPublished 2010-03-15
Not analyzedCVE-2010-10541 file
ExploitDB

Zigurrat Farsi CMS - '/manager/textbox.asp' SQL Injection

ExploitDB exploitPublished 2010-03-15
Not analyzedUnlinked1 file
ExploitDB

Eshopbuilde CMS - SQL Injection

ExploitDB exploitPublished 2009-11-30
ScannerCVE-2009-41551 file

EDB-10253

Analysisdeepseek-v4-pro:cloud ·

Technical assessment

The artifact is a text writeup that lists multiple SQL injection entry points in Eshopbuilde CMS. It provides example URLs with test payloads (e.g., '@@version', 'JyI%3D', '%00') that are designed to detect or validate the presence of SQL injection vulnerabilities by observing application responses, not to extract data or gain access. No exploit code is present.

Backdoor review

No backdoor observed in reviewed code

The supplied text is a plain-text vulnerability disclosure describing SQL injection vectors in Eshopbuilde CMS. It contains no executable code, no instructions for the reader to run anything, and no concealed or deceptive payload. The content is limited to parameter names, example URLs, and remediation advice.

ClassificationScanner
Model confidence95%
AuthenticationNot required
LanguagesEnglish
Target softwareEshopbuilde CMS
Attack typesSQL Injection
Evidence & reasoningClassification basis · observed behavior · safety review
Technical evidence

Classification basis and observed behavior

Classification basis

The artifact contains only example URLs with test payloads (e.g., '@@version', 'JyI%3D', '%00') that are typical of vulnerability detection/validation, not exploitation. It lacks any code to extract data, establish a shell, or perform post-exploitation actions. The content is a writeup describing injection points, but the provided payloads function as a scanner to confirm SQL injection.

exploits/asp/webapps/10253.txt:26-28exploits/asp/webapps/10253.txt:24-68

Requirements

  • Target running Eshopbuilde CMS with accessible vulnerable ASP scriptsexploits/asp/webapps/10253.txt:24-28

Observed behavior

  • Provides example HTTP requests with SQL injection test strings in parameters like sitebid to detect vulnerabilityexploits/asp/webapps/10253.txt:26-28
  • Lists multiple vulnerable scripts and parameters without providing data extraction or command execution logicexploits/asp/webapps/10253.txt:24-68
Safety-review evidence

Behaviors behind the backdoor verdict

Observables

Vulnerability Disclosure
Payload withheldThe file documents multiple SQL injection points across several ASP scripts, consistent with the associated CVE-2009-4155.exploits/asp/webapps/10253.txt:3exploits/asp/webapps/10253.txt:24-68
Review boundaries

What the analysis did not establish

  • Only the single text file from ExploitDB is analyzed; no external tools, libraries, or referenced resources are expanded.
  • The artifact does not include any executable code or scripts; classification is based solely on the provided text content.
  • Only the single text file (10253.txt) was reviewed; no external resources, tools, or referenced URLs were fetched or analyzed.
  • The review does not assess the correctness or completeness of the vulnerability disclosure.
Model interpretation

This review is limited to the supplied PoC code and context. It does not assert that the code works or is safe to execute.

ExploitDB

Elkagroup Elkapax - 'q' Cross-Site Scripting

ExploitDB exploitPublished 2009-08-13
Not analyzedCVE-2009-29301 file
ExploitDB

Yektaweb Academic Web Tools CMS 1.4.2.8/1.5.7 - Multiple Cross-Site Scripting Vulnerabilities

ExploitDB exploitPublished 2009-03-02
Not analyzedUnlinked1 file