CVE-2009-3148
PortalXP Teacher Edition 1.2 - SQL Injection via id or assignment_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3148. PoCs published by SirGod.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in PortalXP Teacher Edition 1.2, allowing unauthorized extraction of teacher credentials via crafted UNION-based SQL queries.
Description
Multiple SQL injection vulnerabilities in PortalXP Teacher Edition 1.2 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) calendar.php, (2) news.php, and (3) links.php; and the (4) assignment_id parameter to assignments.php.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in PortalXP Teacher Edition 1.2, allowing unauthorized extraction of teacher credentials via crafted UNION-based SQL queries.