Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-1910. PoCs published by YEnH4ckEr.
AI-analyzed exploit summary This Perl script exploits a blind SQL injection vulnerability in RTWebalbum 1.0.462 via the 'AlbumID' GET parameter. It automates the extraction of the admin password from the database by brute-forcing each character using ASCII values.
Description
SQL injection vulnerability in index.php in RTWebalbum 1.0.462 allows remote attackers to execute arbitrary SQL commands via the AlbumId parameter.
Exploits (1)
This Perl script exploits a blind SQL injection vulnerability in RTWebalbum 1.0.462 via the 'AlbumID' GET parameter. It automates the extraction of the admin password from the database by brute-forcing each character using ASCII values.