Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-2269. PoCs published by Securitylab Security Research.
AI-analyzed exploit summary This exploit leverages a SQL injection vulnerability in EmpireCMS 4.7 by injecting a malicious payload into the CLIENT-IP header. It extracts the admin username, password, and random value from the phome_enewsuser table.
Description
SQL injection vulnerability in Empire CMS 5.1 allows remote attackers to execute arbitrary SQL commands via the bid parameter to the default URI under e/tool/gbook/.
Exploits (1)
This exploit leverages a SQL injection vulnerability in EmpireCMS 4.7 by injecting a malicious payload into the CLIENT-IP header. It extracts the admin username, password, and random value from the phome_enewsuser table.