Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-2036. PoCs published by YEnH4ckEr.
AI-analyzed exploit summary This exploit demonstrates a blind SQL injection vulnerability in Open Biller 0.1 via the 'username' parameter in the login form. It brute-forces the length and characters of the admin username by leveraging time-based or boolean-based SQLi techniques.
Description
SQL injection vulnerability in index.php in Open Biller 0.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.
Exploits (1)
This exploit demonstrates a blind SQL injection vulnerability in Open Biller 0.1 via the 'username' parameter in the login form. It brute-forces the length and characters of the admin username by leveraging time-based or boolean-based SQLi techniques.