CVE-2009-2152
AdaptWeb 0.9.2 - SQL Injection via CodigoDisciplina Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2152. PoCs published by SirGod.
AI-analyzed exploit summary The exploit demonstrates two vulnerabilities in AdaptWeb 0.9.2: a Local File Inclusion (LFI) via the 'newlang' parameter and an SQL Injection via the 'opcao' parameter. Both PoCs are functional and include specific payloads to exploit the vulnerabilities.
Description
SQL injection vulnerability in a_index.php in AdaptWeb 0.9.2 allows remote attackers to execute arbitrary SQL commands via the CodigoDisciplina parameter in a TopicosCadastro1 action.
Exploits (1)
The exploit demonstrates two vulnerabilities in AdaptWeb 0.9.2: a Local File Inclusion (LFI) via the 'newlang' parameter and an SQL Injection via the 'opcao' parameter. Both PoCs are functional and include specific payloads to exploit the vulnerabilities.