CVE-2009-3315

NeLogic Nephp Publisher Enterprise 3.5.9 and 4.5 - SQL Injection via Username Field

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-3315. PoCs published by learn3r hacker.

AI-analyzed exploit summary This is a writeup describing SQL injection techniques to bypass authentication in NEPHP publisher v3.5.9 or lower. It provides example payloads for username and password fields to exploit the vulnerability.

Description

SQL injection vulnerability in admin/index.php in NeLogic Nephp Publisher Enterprise 3.5.9 and 4.5 allows remote attackers to execute arbitrary SQL commands via the Username field.

Exploits (1)

exploitdb WRITEUP VERIFIED
by learn3r hacker · textwebappsphp
https://www.exploit-db.com/exploits/9712

This is a writeup describing SQL injection techniques to bypass authentication in NEPHP publisher v3.5.9 or lower. It provides example payloads for username and password fields to exploit the vulnerability.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: NEPHP publisher v3.5.9 or lower
No auth needed
Prerequisites: Access to the login page of the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/36444
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/53332
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/9712

Scores

EPSS 0.0096
EPSS Percentile 56.9%

Details

CWE
CWE-89
Status published
Products (2)
nelogic/nephp_publisher 3.5.9
nelogic/nephp_publisher 4.5
Published Sep 23, 2009
Tracked Since Feb 18, 2026