Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-2080. PoCs published by ThE g0bL!N.
AI-analyzed exploit summary This exploit demonstrates SQL injection and information disclosure vulnerabilities in MRCGIGUY The Ticket System 2.0. It includes a SQLi payload to extract database information and URLs to access admin configuration and password change pages without authentication.
Description
admin.php in MRCGIGUY The Ticket System 2.0 does not properly restrict access, which allows remote attackers to (1) obtain sensitive configuration information via the editconfig action or (2) change the administrator's password via the id parameter in an editop action.
Exploits (1)
This exploit demonstrates SQL injection and information disclosure vulnerabilities in MRCGIGUY The Ticket System 2.0. It includes a SQLi payload to extract database information and URLs to access admin configuration and password change pages without authentication.