CVE-2009-3119
Download System mSF for PHP-Fusion - SQL Injection via screen.php view_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3119. PoCs published by Inj3ct0r.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in PHP-fusion dsmsf's screen.php file. The vulnerability arises from improper sanitization of the 'view_id' parameter, allowing an attacker to inject SQL queries.
Description
SQL injection vulnerability in screen.php in the Download System mSF (dsmsf) module for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the view_id parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in PHP-fusion dsmsf's screen.php file. The vulnerability arises from improper sanitization of the 'view_id' parameter, allowing an attacker to inject SQL queries.