Exploitation Summary
EIP tracks 2 public exploits for CVE-2009-1038. PoCs published by SirGod, Alkindiii.
AI-analyzed exploit summary This exploit demonstrates blind SQL injection and SQL injection vulnerabilities in YAP 1.1.1. The blind SQLi allows unauthorized data extraction via time-based techniques, while the SQLi requires admin authentication to dump user credentials.
Description
Multiple SQL injection vulnerabilities in YAP Blog 1.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) image_id parameter to comments.php, and remote authenticated administrators to execute arbitrary SQL commands via the (2) user parameter in a modif action to admin/index.php.
Exploits (2)
This exploit demonstrates blind SQL injection and SQL injection vulnerabilities in YAP 1.1.1. The blind SQLi allows unauthorized data extraction via time-based techniques, while the SQLi requires admin authentication to dump user credentials.
This is a writeup describing a Local File Inclusion (LFI) vulnerability in YAP v1.1.1. The exploit details how to manipulate the 'page' parameter to include arbitrary local files via null byte injection.