CVE-2009-3528
MyMsg 1.0.3 - Authenticated SQL Injection via Profile.php uid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3528. PoCs published by Monster-Dz.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in MyMsg 1.0.3 via the 'uid' parameter in Profile.php, allowing an attacker to extract admin credentials from the database. The exploit requires authentication and leverages a UNION-based SQLi technique.
Description
SQL injection vulnerability in Profile.php in MyMsg 1.0.3 allows remote authenticated users to execute arbitrary SQL commands via the uid parameter in a show action.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in MyMsg 1.0.3 via the 'uid' parameter in Profile.php, allowing an attacker to extract admin credentials from the database. The exploit requires authentication and leverages a UNION-based SQLi technique.