CVE-2009-3531
Universe CMS 1.0.6 - SQL Injection via vnews.php id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3531. PoCs published by Mr.tro0oqy.
AI-analyzed exploit summary This exploit targets a SQL injection vulnerability in Universe CMS 1.0.6 via the 'id' parameter in vnews.php. It extracts admin credentials by injecting a UNION-based SQL query to retrieve username and password hashes from the database.
Description
SQL injection vulnerability in vnews.php in Universe CMS 1.0.6 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
This exploit targets a SQL injection vulnerability in Universe CMS 1.0.6 via the 'id' parameter in vnews.php. It extracts admin credentials by injecting a UNION-based SQL query to retrieve username and password hashes from the database.