CVE-2009-3175
Model Agency Manager PRO - SQL Injection via user_id or id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3175. PoCs published by R3d-D3V!L.
AI-analyzed exploit summary This exploit demonstrates a remote SQL injection vulnerability in Model Agency Manager PRO via the 'user_id' parameter in view.php. The PoC uses a UNION-based SQLi to extract database user information.
Description
Multiple SQL injection vulnerabilities in Model Agency Manager PRO (formerly Modeling Agency Content Management Script) allow remote attackers to execute arbitrary SQL commands via the user_id parameter to (1) view.php, (2) photos.php, and (3) motm.php; and the (4) id parameter to forum_message.php.
Exploits (1)
This exploit demonstrates a remote SQL injection vulnerability in Model Agency Manager PRO via the 'user_id' parameter in view.php. The PoC uses a UNION-based SQLi to extract database user information.