Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-1487. PoCs published by YEnH4ckEr.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass via SQL injection in the login form and insecure cookie handling, as well as a local file inclusion (LFI) vulnerability in the admin module. The PoC provides clear steps to exploit these vulnerabilities in FunGamez RC-1.
Description
SQL injection vulnerability in pages/login.php in FunGamez RC1 allows remote attackers to execute arbitrary SQL commands via the login_user (aka username) parameter. NOTE: some of these details are obtained from third party information.
Exploits (1)
This exploit demonstrates an authentication bypass via SQL injection in the login form and insecure cookie handling, as well as a local file inclusion (LFI) vulnerability in the admin module. The PoC provides clear steps to exploit these vulnerabilities in FunGamez RC-1.