CVE-2009-1843
Flash Quiz Beta 2 - SQL Injection via Quiz or Order Number Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1843. PoCs published by YEnH4ckEr.
AI-analyzed exploit summary This exploit demonstrates multiple SQL injection vulnerabilities in Flash Quiz Beta 2, allowing attackers to extract sensitive information such as database credentials and user data via crafted GET requests.
Description
Multiple SQL injection vulnerabilities in Flash Quiz Beta 2 allow remote attackers to execute arbitrary SQL commands via the (1) quiz parameter to (a) num_questions.php, (b) answers.php, (c) high_score.php, (d) high_score_web.php, (e) results_table_web.php, and (f) question.php; and the (2) order_number parameter to (g) answers.php and (h) question.php.
Exploits (1)
This exploit demonstrates multiple SQL injection vulnerabilities in Flash Quiz Beta 2, allowing attackers to extract sensitive information such as database credentials and user data via crafted GET requests.