Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-1952. PoCs published by SirGod.
AI-analyzed exploit summary This exploit demonstrates SQL injection for authentication bypass and XSS in PropertyMax Pro FREE. The SQLi bypasses login by manipulating the query, while the XSS executes arbitrary JavaScript via a crafted URL parameter.
Description
Multiple SQL injection vulnerabilities in the administrative login feature in PropertyMax Pro FREE 0.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
Exploits (1)
This exploit demonstrates SQL injection for authentication bypass and XSS in PropertyMax Pro FREE. The SQLi bypasses login by manipulating the query, while the XSS executes arbitrary JavaScript via a crafted URL parameter.