CVE-2009-1746
Dian Gemilang DGNews 3.0 Beta - SQL Injection via berita.php id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1746. PoCs published by Cyber-Zone.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in DGNews 3.0 Beta via the 'id' parameter in berita.php, allowing an attacker to extract database version information. The payload uses a UNION-based SQLi technique to retrieve data from the MySQL server.
Description
SQL injection vulnerability in berita.php in Dian Gemilang DGNews 3.0 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in DGNews 3.0 Beta via the 'id' parameter in berita.php, allowing an attacker to extract database version information. The payload uses a UNION-based SQLi technique to retrieve data from the MySQL server.