CVE-2009-1853
Kensei Board < 2.0.0b - SQL Injection via f and t Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-1853. PoCs published by cOndemned.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Kensei Board <= 2.0.0b via the 'f' and 't' parameters, allowing unauthorized data extraction from the database. The PoC includes crafted URLs that bypass authentication and dump user credentials.
Description
Multiple SQL injection vulnerabilities in index.php in Kensei Board 2.0 BETA (aka 2.0.0b) and earlier allow remote attackers to execute arbitrary SQL commands via the (1) f and (2) t parameters in a showforum action.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in Kensei Board <= 2.0.0b via the 'f' and 't' parameters, allowing unauthorized data extraction from the database. The PoC includes crafted URLs that bypass authentication and dump user credentials.