Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-2639. PoCs published by ThE g0bL!N.
AI-analyzed exploit summary This exploit demonstrates SQL injection and information disclosure vulnerabilities in MRCGIGUY The Ticket System 2.0. It includes a SQLi payload to extract database information and URLs to access admin configuration and password change pages without authentication.
Description
SQL injection vulnerability in admin.php in MRCGIGUY The Ticket System 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewticket action.
Exploits (1)
This exploit demonstrates SQL injection and information disclosure vulnerabilities in MRCGIGUY The Ticket System 2.0. It includes a SQLi payload to extract database information and URLs to access admin configuration and password change pages without authentication.