CVE-2009-2443
Siteframe 3.2.x - Information Exposure via phpinfo.php Direct Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2443. PoCs published by NoGe.
AI-analyzed exploit summary This exploit demonstrates SQL injection and information disclosure vulnerabilities in Siteframe CMS 3.2.x. The SQLi allows attackers to extract user credentials via a crafted query, while the phpinfo.php file exposes server configuration details.
Description
Siteframe 3.2.3, and other 3.2.x versions, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.
Exploits (1)
This exploit demonstrates SQL injection and information disclosure vulnerabilities in Siteframe CMS 3.2.x. The SQLi allows attackers to extract user credentials via a crafted query, while the phpinfo.php file exposes server configuration details.