Description
Multiple SQL injection vulnerabilities in PHP Dir Submit (aka WebsiteSubmitter and Submitter Script) allow remote attackers to bypass authentication and gain administrative access via the (1) username and (2) password parameters.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by snakespc · textwebappsphp
https://www.exploit-db.com/exploits/8710
References (4)
Core 4
Core References
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/35003
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1365
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/35125
Exploit, Third Party Advisory exploit
x_refsource_exploit-db
https://www.exploit-db.com/exploits/8710
Scores
EPSS
0.0020
EPSS Percentile
41.7%
Details
CWE
CWE-89
Status
published
Products (1)
phpdirsubmit/php_dir_submit
Published
May 26, 2009
Tracked Since
Feb 18, 2026