CVE-2009-3190
PAD Site Scripts 3.6 - SQL Injection via Search or RSS Category Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3190. PoCs published by Mr.SQL.
AI-analyzed exploit summary The exploit demonstrates a remote SQL injection vulnerability in PAD Site Scripts v3.6 via the 'list.php' parameter 'string'. It also includes an XSS vulnerability in 'rss.php' and 'opml.php' via the 'cat' parameter. The SQLi payload extracts table and column names from the INFORMATION_SCHEMA.
Description
Multiple SQL injection vulnerabilities in PAD Site Scripts 3.6 allow remote attackers to execute arbitrary SQL commands via the (1) search parameter to list.php and (2) cat parameter to rss.php.
Exploits (1)
The exploit demonstrates a remote SQL injection vulnerability in PAD Site Scripts v3.6 via the 'list.php' parameter 'string'. It also includes an XSS vulnerability in 'rss.php' and 'opml.php' via the 'cat' parameter. The SQLi payload extracts table and column names from the INFORMATION_SCHEMA.