Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-2553. PoCs published by JIKO.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in SuperSimpleBlogScriptV2_5_4 via the 'entry' parameter in comments.php. The PoC uses a UNION-based SQLi to extract database version and user information.
Description
Multiple SQL injection vulnerabilities in comments.php in Super Simple Blog Script 2.5.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the entry parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in SuperSimpleBlogScriptV2_5_4 via the 'entry' parameter in comments.php. The PoC uses a UNION-based SQLi to extract database version and user information.