CVE-2009-3315
NeLogic Nephp Publisher Enterprise 3.5.9 and 4.5 - SQL Injection via Username Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3315. PoCs published by learn3r hacker.
AI-analyzed exploit summary This is a writeup describing SQL injection techniques to bypass authentication in NEPHP publisher v3.5.9 or lower. It provides example payloads for username and password fields to exploit the vulnerability.
Description
SQL injection vulnerability in admin/index.php in NeLogic Nephp Publisher Enterprise 3.5.9 and 4.5 allows remote attackers to execute arbitrary SQL commands via the Username field.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by learn3r hacker · textwebappsphp
https://www.exploit-db.com/exploits/9712
This is a writeup describing SQL injection techniques to bypass authentication in NEPHP publisher v3.5.9 or lower. It provides example payloads for username and password fields to exploit the vulnerability.
Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:
NEPHP publisher v3.5.9 or lower
No auth needed
Prerequisites:
Access to the login page of the target application
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (3)
Core 3
Core References
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/36444
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/53332
Exploit, Third Party Advisory exploit
x_refsource_exploit-db
http://www.exploit-db.com/exploits/9712
Scores
EPSS
0.0096
EPSS Percentile
56.9%
Details
CWE
CWE-89
Status
published
Products (2)
nelogic/nephp_publisher
3.5.9
nelogic/nephp_publisher
4.5
Published
Sep 23, 2009
Tracked Since
Feb 18, 2026