CVE-2009-3349
Datavore Gyro 5.0 - SQL Injection via cid Parameter in Home Component
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3349. PoCs published by OoN_Boy.
AI-analyzed exploit summary This exploit demonstrates SQL injection and XSS vulnerabilities in Gyro V5.0 by manipulating the 'cid' parameter in the 'op=cat' endpoint. It includes proof-of-concept URLs showing how to extract database version information and execute arbitrary JavaScript.
Description
SQL injection vulnerability in Datavore Gyro 5.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter in a cat action to the home component.
Exploits (1)
This exploit demonstrates SQL injection and XSS vulnerabilities in Gyro V5.0 by manipulating the 'cid' parameter in the 'op=cat' endpoint. It includes proof-of-concept URLs showing how to extract database version information and execute arbitrary JavaScript.