CVE-2009-1038

YAP Blog 1.1.1 - SQL Injection via Image ID Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2009-1038. PoCs published by SirGod, Alkindiii.

AI-analyzed exploit summary This exploit demonstrates blind SQL injection and SQL injection vulnerabilities in YAP 1.1.1. The blind SQLi allows unauthorized data extraction via time-based techniques, while the SQLi requires admin authentication to dump user credentials.

Description

Multiple SQL injection vulnerabilities in YAP Blog 1.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) image_id parameter to comments.php, and remote authenticated administrators to execute arbitrary SQL commands via the (2) user parameter in a modif action to admin/index.php.

Exploits (2)

exploitdb WORKING POC VERIFIED
by SirGod · textwebappsphp
https://www.exploit-db.com/exploits/8217

This exploit demonstrates blind SQL injection and SQL injection vulnerabilities in YAP 1.1.1. The blind SQLi allows unauthorized data extraction via time-based techniques, while the SQLi requires admin authentication to dump user credentials.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: YAP 1.1.1
Auth required
Prerequisites: Access to the target application · Admin credentials for SQLi
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by Alkindiii · textwebappsphp
https://www.exploit-db.com/exploits/8207

This is a writeup describing a Local File Inclusion (LFI) vulnerability in YAP v1.1.1. The exploit details how to manipulate the 'page' parameter to include arbitrary local files via null byte injection.

Classification
Writeup 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: YAP v1.1.1
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit vdb-entry x_refsource_osvdb
http://osvdb.org/52762
Exploit vdb-entry x_refsource_osvdb
http://osvdb.org/52761
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8217
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34274

Scores

EPSS 0.0088
EPSS Percentile 54.2%

Details

CWE
CWE-89
Status published
Products (1)
yap/yap_blog 1.1.1
Published Mar 20, 2009
Tracked Since Feb 18, 2026