CVE-2009-2895
Ultimate Regnow Affiliate 3.0 - SQL Injection via RSS cat Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2895. PoCs published by Chip d3 bi0s.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Ultimate Regnow Affiliate (URA) 3.0 via the 'cat' parameter in rss.php. It extracts admin credentials from the 'ura_settings' table using a UNION-based SQL injection technique.
Description
SQL injection vulnerability in rss.php in Ultimate Regnow Affiliate (URA) 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Ultimate Regnow Affiliate (URA) 3.0 via the 'cat' parameter in rss.php. It extracts admin credentials from the 'ura_settings' table using a UNION-based SQL injection technique.