CVE-2009-3436
MaxWebPortal - SQL Injection via FORUM_ID or CAT_ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3436. PoCs published by OoN_Boy.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in MaxWebPortal by injecting a SQL query into the CAT_ID parameter. The payload uses the CONVERT function to trigger an error that leaks the database version.
Description
Multiple SQL injection vulnerabilities in forum.asp in MaxWebPortal allow remote attackers to execute arbitrary SQL commands via the (1) FORUM_ID or (2) CAT_ID parameter. NOTE: this might overlap CVE-2005-1417.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in MaxWebPortal by injecting a SQL query into the CAT_ID parameter. The payload uses the CONVERT function to trigger an error that leaks the database version.