CVE-2009-1787

Phpdirsubmit Php Dir Submit - SQL Injection

Title source: rule
STIX 2.1

Description

Multiple SQL injection vulnerabilities in PHP Dir Submit (aka WebsiteSubmitter and Submitter Script) allow remote attackers to bypass authentication and gain administrative access via the (1) username and (2) password parameters.

Exploits (1)

exploitdb WORKING POC VERIFIED
by snakespc · textwebappsphp
https://www.exploit-db.com/exploits/8710

References (4)

Core 4
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/35003
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1365
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35125
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8710

Scores

EPSS 0.0020
EPSS Percentile 41.7%

Details

CWE
CWE-89
Status published
Products (1)
phpdirsubmit/php_dir_submit
Published May 26, 2009
Tracked Since Feb 18, 2026