CVE-2009-2605
Traidnt Up 2.0 - SQL Injection via trupuser and truppassword Cookies
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2605. PoCs published by Qabandi.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass via SQL injection in Traidnt Up version 2.0 by manipulating cookie values. The vulnerability arises from improper filtering of user-supplied input in the adminquery.php file, allowing an attacker to bypass authentication by injecting SQL into the trupuser and truppassword cookies.
Description
Multiple SQL injection vulnerabilities in adminquery.php in Traidnt Up 2.0 allow remote attackers to execute arbitrary SQL commands via (1) trupuser and (2) truppassword cookies to uploadcp/index.php.
Exploits (1)
This exploit demonstrates an authentication bypass via SQL injection in Traidnt Up version 2.0 by manipulating cookie values. The vulnerability arises from improper filtering of user-supplied input in the adminquery.php file, allowing an attacker to bypass authentication by injecting SQL into the trupuser and truppassword cookies.