CVE-2009-1224
vsp_stats_processor 0.45 - SQL Injection via gameID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1224. PoCs published by Dimi4.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in vsp stats processor. The vulnerability allows an attacker to extract sensitive information such as user, database, and version details by manipulating the gameID parameter in the gamestat.php file.
Description
SQL injection vulnerability in vsp-core/pub/themes/bismarck/gamestat.php in vsp stats processor 0.45 allows remote attackers to execute arbitrary SQL commands via the gameID parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in vsp stats processor. The vulnerability allows an attacker to extract sensitive information such as user, database, and version details by manipulating the gameID parameter in the gamestat.php file.