Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-0963. PoCs published by BugReport.IR.
AI-analyzed exploit summary This is a writeup describing a SQL injection vulnerability in PHPRunner 4.2. It provides details on vulnerable parameters and example URLs for exploitation but does not include executable exploit code.
Description
Multiple SQL injection vulnerabilities in PHPRunner 4.2, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the SearchField parameter to (1) UserView_list.php, (2) orders_list.php, (3) users_list.php, and (4) Administrator_list.php.
Exploits (1)
This is a writeup describing a SQL injection vulnerability in PHPRunner 4.2. It provides details on vulnerable parameters and example URLs for exploitation but does not include executable exploit code.