CVE-2009-3081

Uiga Church Portal - SQL Injection via Month Parameter in Calendar Action

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-3081.

AI-analyzed exploit summary This exploit demonstrates a remote SQL injection vulnerability in Uiga Church Portal's index.php via the 'view' parameter. The crafted URL injects a UNION-based SQL query to extract database version, user, and database name.

Description

SQL injection vulnerability in index.php in Uiga Church Portal allows remote attackers to execute arbitrary SQL commands via the month parameter in a calendar action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Exploits (1)

exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/9535

This exploit demonstrates a remote SQL injection vulnerability in Uiga Church Portal's index.php via the 'view' parameter. The crafted URL injects a UNION-based SQL query to extract database version, user, and database name.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Uiga Church Portal
No auth needed
Prerequisites: Access to the target web application
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit vdb-entry x_refsource_osvdb
http://osvdb.org/57464
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36479
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/52893

Scores

EPSS 0.0096
EPSS Percentile 56.9%

Details

CWE
CWE-89
Status published
Products (1)
uiga/church_portal
Published Sep 04, 2009
Tracked Since Feb 18, 2026