Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-2023. PoCs published by Ams.
AI-analyzed exploit summary This Perl exploit targets a SQL injection vulnerability in Shop Script Pro 2.12 via the 'current_currency' parameter, allowing an attacker to write a PHP shell to the server. It attempts to discover the server path via 'linkpoint.php' or brute-forces common paths.
Description
SQL injection vulnerability in index.php in Shop-Script Pro 2.12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the current_currency parameter.
Exploits (1)
This Perl exploit targets a SQL injection vulnerability in Shop Script Pro 2.12 via the 'current_currency' parameter, allowing an attacker to write a PHP shell to the server. It attempts to discover the server path via 'linkpoint.php' or brute-forces common paths.