CVE-2009-2926
PHP Competition System BETA 0.84 - SQL Injection via Day or Pageno Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-2926. PoCs published by Mr.SQL.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in PHP Competition System BETA <= V0.84 via the 'show_matchs.php' and 'persons.php' parameters. It allows an attacker to extract user credentials (name, password, email) from the database.
Description
Multiple SQL injection vulnerabilities in PHP Competition System BETA 0.84 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) day parameter to show_matchs.php and (2) pageno parameter to persons.php.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in PHP Competition System BETA <= V0.84 via the 'show_matchs.php' and 'persons.php' parameters. It allows an attacker to extract user credentials (name, password, email) from the database.