Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-3755. PoCs published by eLwaux.
AI-analyzed exploit summary The exploit demonstrates multiple SQL injection and XSS vulnerabilities in phpBMS v0.96, including PoC payloads for extracting database information and executing arbitrary SQL queries. It also includes path disclosure vectors.
Description
Multiple cross-site scripting (XSS) vulnerabilities in phpBMS 0.96 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php and (2) modules\base\myaccount.php; and the PATH_INFO to (3) modules_view.php, (4) tabledefs_options.php, and (5) adminsettings.php in phpbms\modules\base\.
Exploits (1)
The exploit demonstrates multiple SQL injection and XSS vulnerabilities in phpBMS v0.96, including PoC payloads for extracting database information and executing arbitrary SQL queries. It also includes path disclosure vectors.