CVE-2009-3116
Uiga Church Portal - SQL Injection via Year Parameter in Calendar Action
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3116. PoCs published by Mr.SQL.
AI-analyzed exploit summary This exploit demonstrates a remote SQL injection vulnerability in Uiga Church Portal's index.php view parameter. It allows an attacker to extract database information such as version, user, and database name via a crafted URL.
Description
SQL injection vulnerability in index.php in Uiga Church Portal allows remote attackers to execute arbitrary SQL commands via the year parameter in a calendar action.
Exploits (1)
This exploit demonstrates a remote SQL injection vulnerability in Uiga Church Portal's index.php view parameter. It allows an attacker to extract database information such as version, user, and database name via a crafted URL.