CVE-2009-0829
QuoteBook - SQL Injection via MyBox, selectFavorites, QuoteName, or QuoteText Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-0829. PoCs published by Moudi.
AI-analyzed exploit summary This is a writeup describing a file disclosure vulnerability in QuoteBook. The exploit details how accessing a specific file (poll.inc) can leak database credentials due to improper configuration handling.
Description
Multiple SQL injection vulnerabilities in QuoteBook allow remote attackers to execute arbitrary SQL commands via the (1) MyBox and (2) selectFavorites parameters to (a) quotes.php and the (3) QuoteName and (4) QuoteText parameters to (b) quotesadd.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This is a writeup describing a file disclosure vulnerability in QuoteBook. The exploit details how accessing a specific file (poll.inc) can leak database credentials due to improper configuration handling.