CVE-2009-2573
MiniTwitter 0.2 beta - Authenticated SQL Injection via User Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2573. PoCs published by YEnH4ckEr.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in MiniTwitter v0.2-Beta. It includes proof-of-concept URLs to extract database version, user, and user credentials (nickname and password hash).
Description
Multiple SQL injection vulnerabilities in MiniTwitter 0.2 beta, when magic_quotes_gpc is disabled, allow remote authenticated users to execute arbitrary SQL commands via the (1) user parameter to (a) index.php and (b) rss.php.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in MiniTwitter v0.2-Beta. It includes proof-of-concept URLs to extract database version, user, and user credentials (nickname and password hash).