CVE-2009-3081
Uiga Church Portal - SQL Injection via Month Parameter in Calendar Action
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3081.
AI-analyzed exploit summary This exploit demonstrates a remote SQL injection vulnerability in Uiga Church Portal's index.php via the 'view' parameter. The crafted URL injects a UNION-based SQL query to extract database version, user, and database name.
Description
SQL injection vulnerability in index.php in Uiga Church Portal allows remote attackers to execute arbitrary SQL commands via the month parameter in a calendar action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
This exploit demonstrates a remote SQL injection vulnerability in Uiga Church Portal's index.php via the 'view' parameter. The crafted URL injects a UNION-based SQL query to extract database version, user, and database name.