CVE-2009-1652
2daybiz Business Community Script - Unauthenticated Privilege Escalation via admin/adminaddeditdetails.php
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1652. PoCs published by TiGeR-Dz.
AI-analyzed exploit summary This exploit demonstrates an Add Admin functionality and a Remote Blind SQL Injection vulnerability in 2daybiz Business Community Script. The SQLi is executed via the 'mid' parameter in member_details.php, allowing unauthorized database queries.
Description
admin/adminaddeditdetails.php in Business Community Script does not properly restrict access, which allows remote attackers to gain privileges and add administrators via a direct request.
Exploits (1)
This exploit demonstrates an Add Admin functionality and a Remote Blind SQL Injection vulnerability in 2daybiz Business Community Script. The SQLi is executed via the 'mid' parameter in member_details.php, allowing unauthorized database queries.