Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-0728. PoCs published by StAkeR.
AI-analyzed exploit summary This exploit targets a SQL injection vulnerability in the MDPro Module My_eGallery. It crafts a malicious SQL query to extract user credentials (username and password) from the database by manipulating the 'pid' parameter.
Description
SQL injection vulnerability in the My_eGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to execute arbitrary SQL commands via the pid parameter in a showpic action to index.php.
Exploits (1)
This exploit targets a SQL injection vulnerability in the MDPro Module My_eGallery. It crafts a malicious SQL query to extract user credentials (username and password) from the database by manipulating the 'pid' parameter.