Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-2394. PoCs published by SecurityRules.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Messages Library v2.0's cat.php script. It uses a UNION-based SQLi to extract admin credentials (Modname and ModPassword) from the modretor table.
Description
SQL injection vulnerability in cat.php in SMSPages 1.0 in Mr.Saphp Arabic Script Mobile (aka Messages Library) 2.0 allows remote attackers to execute arbitrary SQL commands via the CatID parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Messages Library v2.0's cat.php script. It uses a UNION-based SQLi to extract admin credentials (Modname and ModPassword) from the modretor table.