Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-0121. PoCs published by darkjoker.
AI-analyzed exploit summary This exploit demonstrates a blind SQL injection vulnerability in Goople CMS <= 1.8.2 by brute-forcing username and password characters via time-based delays. It uses ASCII substring comparisons and BENCHMARK to infer data.
Description
SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 allows remote attackers to execute arbitrary SQL commands via the password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This exploit demonstrates a blind SQL injection vulnerability in Goople CMS <= 1.8.2 by brute-forcing username and password characters via time-based delays. It uses ASCII substring comparisons and BENCHMARK to infer data.