CVE-2009-2776

Smart ASP Survey - SQL Injection via showresult.asp catid Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-2776. PoCs published by Moudi.

AI-analyzed exploit summary The provided text describes a SQL injection vulnerability in Smart ASP Survey, where the 'catid' parameter in 'showresult.asp' is not properly sanitized. This allows attackers to manipulate SQL queries, potentially leading to unauthorized data access or further exploitation.

Description

SQL injection vulnerability in showresult.asp in Smart ASP Survey allows remote attackers to execute arbitrary SQL commands via the catid parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Moudi · textwebappsasp
https://www.exploit-db.com/exploits/34687

The provided text describes a SQL injection vulnerability in Smart ASP Survey, where the 'catid' parameter in 'showresult.asp' is not properly sanitized. This allows attackers to manipulate SQL queries, potentially leading to unauthorized data access or further exploitation.

Classification
Writeup 80%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: Smart ASP Survey
No auth needed
Prerequisites: Access to the vulnerable endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36028
Exploit vdb-entry x_refsource_osvdb
http://osvdb.org/56575

Scores

EPSS 0.0099
EPSS Percentile 58.0%

Details

CWE
CWE-89
Status published
Products (1)
sellatsite.com/smart_asp_survey
Published Aug 14, 2009
Tracked Since Feb 18, 2026