Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-0528. PoCs published by darkjoker.
AI-analyzed exploit summary This exploit leverages a blind SQL injection vulnerability in IF-CMS <= 2.0 to extract the admin password character by character using time-based techniques. It sends crafted HTTP requests to infer password characters based on response delays.
Description
SQL injection vulnerability in frame.php in Rhadrix If-CMS 2.07 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
This exploit leverages a blind SQL injection vulnerability in IF-CMS <= 2.0 to extract the admin password character by character using time-based techniques. It sends crafted HTTP requests to infer password characters based on response delays.