Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-1323. PoCs published by Osirys.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in WebFileExplorer 3.1, allowing authentication bypass via a crafted login request. It also shows how an attacker can upload arbitrary files (e.g., PHP shells) post-authentication, leading to remote command execution.
Description
SQL injection vulnerability in body.asp in Web File Explorer 3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in WebFileExplorer 3.1, allowing authentication bypass via a crafted login request. It also shows how an attacker can upload arbitrary files (e.g., PHP shells) post-authentication, leading to remote command execution.