CVE-2009-0516
BusinessSpace < 1.2 - SQL Injection via Classified Page id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-0516. PoCs published by K-159.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in BusinessSpace <= 1.2 via the 'id' parameter in classified.php. It allows an attacker to retrieve user credentials in plain text through a UNION-based SQL injection.
Description
SQL injection vulnerability in the classified page (classified.php) in BusinessSpace 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in BusinessSpace <= 1.2 via the 'id' parameter in classified.php. It allows an attacker to retrieve user credentials in plain text through a UNION-based SQL injection.