Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-3754. PoCs published by eLwaux.
AI-analyzed exploit summary The exploit demonstrates multiple SQL injection and XSS vulnerabilities in phpBMS v0.96, including PoC payloads for extracting database information and executing arbitrary SQL queries. It also includes path disclosure vectors.
Description
Multiple SQL injection vulnerabilities in phpBMS 0.96 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to modules/bms/invoices_discount_ajax.php, (2) f parameter to dbgraphic.php, and (3) tid parameter in a show action to advancedsearch.php.
Exploits (1)
The exploit demonstrates multiple SQL injection and XSS vulnerabilities in phpBMS v0.96, including PoC payloads for extracting database information and executing arbitrary SQL queries. It also includes path disclosure vectors.