CVE-2009-2735
sun-jester OpenNews 1.0 - SQL Injection via Username Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2735. PoCs published by SirGod.
AI-analyzed exploit summary This exploit demonstrates SQL injection for authentication bypass and remote command execution in OpenNews 1.0. The SQLi bypasses admin authentication, while the RCE leverages unsanitized input in the 'Overall Width' field to execute system commands.
Description
SQL injection vulnerability in admin.php in sun-jester OpenNews 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.
Exploits (1)
This exploit demonstrates SQL injection for authentication bypass and remote command execution in OpenNews 1.0. The SQLi bypasses admin authentication, while the RCE leverages unsanitized input in the 'Overall Width' field to execute system commands.