CVE-2009-0604
php_director < 0.21 - SQL Injection via Searching Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-0604. PoCs published by darkjoker.
AI-analyzed exploit summary This exploit leverages a SQL injection vulnerability in PHP Director <= 0.21 to write a PHP shell to the target system, enabling remote command execution. The exploit crafts a malicious SQL query to create a backdoor shell and then interacts with it to execute arbitrary commands.
Description
SQL injection vulnerability in index.php in PHP Director 0.21 and earlier allows remote attackers to execute arbitrary SQL commands via the searching parameter.
Exploits (1)
This exploit leverages a SQL injection vulnerability in PHP Director <= 0.21 to write a PHP shell to the target system, enabling remote command execution. The exploit crafts a malicious SQL query to create a backdoor shell and then interacts with it to execute arbitrary commands.