CVE-2009-3712
Ebay Clone 2009 - SQL Injection via user_id or item_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3712. PoCs published by MizoZ.
AI-analyzed exploit summary This exploit demonstrates multiple SQL injection vulnerabilities in Ebay Clone 2009, including union-based and blind SQLi via GET parameters. The PoC provides specific URLs with payloads to extract database version information.
Description
Multiple SQL injection vulnerabilities in Ebay Clone 2009 allow remote attackers to execute arbitrary SQL commands via the (1) user_id parameter to feedback.php; and the item_id parameter to (2) view_full_size.php, (3) classifide_ad.php, and (4) crosspromoteitems.php.
Exploits (1)
This exploit demonstrates multiple SQL injection vulnerabilities in Ebay Clone 2009, including union-based and blind SQLi via GET parameters. The PoC provides specific URLs with payloads to extract database version information.