CVE-2009-1229
arcadwy_arcade_script - SQL Injection via User Cookie Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1229. PoCs published by ZoRLu.
AI-analyzed exploit summary This exploit demonstrates an insecure cookie handling vulnerability in Arcadwy Arcade Script, allowing an attacker to bypass authentication by injecting a malicious cookie value. The exploit uses a JavaScript snippet to set a cookie that manipulates a SQL query, effectively granting admin privileges.
Description
SQL injection vulnerability in Arcadwy Arcade Script allows remote attackers to execute arbitrary SQL commands via the user cookie parameter.
Exploits (1)
This exploit demonstrates an insecure cookie handling vulnerability in Arcadwy Arcade Script, allowing an attacker to bypass authentication by injecting a malicious cookie value. The exploit uses a JavaScript snippet to set a cookie that manipulates a SQL query, effectively granting admin privileges.