Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-1247. PoCs published by SirGod.
AI-analyzed exploit summary This exploit demonstrates a Remote File Inclusion (RFI) vulnerability and an SQL Injection (Auth Bypass) in Acute Control Panel 1.0.0. The RFI allows arbitrary file inclusion via the `theme_directory` parameter, while the SQLi bypasses authentication by manipulating the login query.
Description
SQL injection vulnerability in login.php in Acute Control Panel 1.0.0 allows remote attackers to execute arbitrary SQL commands via the username parameter.
Exploits (1)
This exploit demonstrates a Remote File Inclusion (RFI) vulnerability and an SQL Injection (Auth Bypass) in Acute Control Panel 1.0.0. The RFI allows arbitrary file inclusion via the `theme_directory` parameter, while the SQLi bypasses authentication by manipulating the login query.