CVE-2009-1049
Bloginator 1A - SQL Injection via articleCall.php id Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2009-1049. PoCs published by Fireshot.
AI-analyzed exploit summary Exploit for CVE-2009-1050 targeting Bloginator V1A, demonstrating insecure cookie handling for authentication bypass and SQL injection via the 'id' parameter. The PoC includes JavaScript for cookie manipulation and a SQLi payload for arbitrary file disclosure.
Description
SQL injection vulnerability in articleCall.php in Bloginator 1A allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (2)
Exploit for CVE-2009-1050 targeting Bloginator V1A, demonstrating insecure cookie handling for authentication bypass and SQL injection via the 'id' parameter. The PoC includes JavaScript for cookie manipulation and a SQLi payload for arbitrary file disclosure.
This exploit leverages a SQL injection vulnerability in Bloginator V1A to bypass authentication and inject a PHP shell. It uses error-based SQLi to locate the Apache error log path and then writes a malicious PHP file to the target server.