CVE-2009-3226
Almond Classifieds Ads Enterprise and Almond Affiliate Network Classifieds - SQL Injection via replid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3226. PoCs published by Moudi.
AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in AlmondSoft Almond Classifieds, demonstrating how unsanitized user input in the 'replid' parameter can be exploited to manipulate SQL queries. It includes example URLs to test for true/false conditions and database version extraction.
Description
SQL injection vulnerability in index.php in AlmondSoft Almond Classifieds Ads Enterprise and Almond Affiliate Network Classifieds allows remote attackers to execute arbitrary SQL commands via the replid parameter in a manw_repl add_form action. NOTE: some of these details are obtained from third party information.
Exploits (1)
The provided text describes an SQL injection vulnerability in AlmondSoft Almond Classifieds, demonstrating how unsanitized user input in the 'replid' parameter can be exploited to manipulate SQL queries. It includes example URLs to test for true/false conditions and database version extraction.