CVE-2009-2593

Censura 1.16.04 - SQL Injection via itemid Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-2593. PoCs published by Vrs-hCk.

AI-analyzed exploit summary This is a writeup describing Blind SQL Injection and XSS vulnerabilities in Censura v1.16.04. It provides example URLs demonstrating the vulnerabilities but does not include functional exploit code.

Description

SQL injection vulnerability in censura.php in Censura 1.16.04 allows remote attackers to execute arbitrary SQL commands via the itemid parameter in a details action.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Vrs-hCk · textwebappsphp
https://www.exploit-db.com/exploits/9129

This is a writeup describing Blind SQL Injection and XSS vulnerabilities in Censura v1.16.04. It provides example URLs demonstrating the vulnerabilities but does not include functional exploit code.

Classification
Writeup 90%
Attack Type
Sqli | Xss
Complexity
Trivial
Reliability
Theoretical
Target: Censura v1.16.04
No auth needed
Prerequisites: Access to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/35787
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/35637
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/51663
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/55790
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/9129

Scores

EPSS 0.0100
EPSS Percentile 58.3%

Details

CWE
CWE-89
Status published
Products (1)
censura/censura 1.16.04
Published Jul 24, 2009
Tracked Since Feb 18, 2026