Exploitation Summary
EIP tracks 2 public exploits for CVE-2009-0427. PoCs published by ajann.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in DMXReady Member Directory Manager <= 1.1. It allows an attacker to extract admin credentials by injecting malicious SQL queries into the 'cid' parameter.
Description
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Member Directory Manager 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in DMXReady Member Directory Manager <= 1.1. It allows an attacker to extract admin credentials by injecting malicious SQL queries into the 'cid' parameter.
This exploit demonstrates a SQL injection vulnerability in DMXReady Classified Listings Manager <= 1.1. It provides specific URLs and payloads to extract admin credentials from the database.