CVE-2009-0324
BibCiter 1.4 - SQL Injection via idp, idc, or idu Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-0324. PoCs published by nuclear.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in BibCiter 1.4 by manipulating the 'idp', 'idc', and 'idu' parameters in multiple PHP files. The vulnerable function 'get_vatitle' fails to sanitize user input, allowing attackers to execute arbitrary SQL queries.
Description
Multiple SQL injection vulnerabilities in BibCiter 1.4 allow remote attackers to execute arbitrary SQL commands via the (1) idp parameter to reports/projects.php, the (2) idc parameter to reports/contacts.php, and the (3) idu parameter to reports/users.php.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in BibCiter 1.4 by manipulating the 'idp', 'idc', and 'idu' parameters in multiple PHP files. The vulnerable function 'get_vatitle' fails to sanitize user input, allowing attackers to execute arbitrary SQL queries.