CVE-2009-2142

Zip Store Chat 4.0-5.0 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-2142. PoCs published by ByALBAYX.

AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Zip Store Chat 4.0 and 5.0, allowing authentication bypass via crafted login credentials. The PoC provides specific payloads to exploit the vulnerability in the admin panel.

Description

Multiple SQL injection vulnerabilities in admin/index.asp in Zip Store Chat 4.0 and 5.0 allow remote attackers to execute arbitrary SQL commands via the (1) login and (2) senha parameters.

Exploits (1)

exploitdb WORKING POC VERIFIED
by ByALBAYX · textwebappsphp
https://www.exploit-db.com/exploits/8935

This exploit demonstrates an SQL injection vulnerability in Zip Store Chat 4.0 and 5.0, allowing authentication bypass via crafted login credentials. The PoC provides specific payloads to exploit the vulnerability in the admin panel.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Zip Store Chat 4.0 and 5.0
No auth needed
Prerequisites: Access to the admin login page
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (3)

Core 3
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1581
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35417
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8935

Scores

EPSS 0.0101
EPSS Percentile 58.6%

Details

CWE
CWE-89
Status published
Products (2)
zipstore/zip_store_chat 4.0
zipstore/zip_store_chat 5.0
Published Jun 22, 2009
Tracked Since Feb 18, 2026