CVE-2009-3756
phpBMS 0.96 - Exposure of Sensitive Information via Direct Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3756. PoCs published by eLwaux.
AI-analyzed exploit summary The exploit demonstrates multiple SQL injection and XSS vulnerabilities in phpBMS v0.96, including PoC payloads for extracting database information and executing arbitrary SQL queries. It also includes path disclosure vectors.
Description
phpBMS 0.96 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php, (2) header.php, (3) the show action in advancedsearch.php, and (4) choicelist.php, which reveals the installation path in an error message.
Exploits (1)
The exploit demonstrates multiple SQL injection and XSS vulnerabilities in phpBMS v0.96, including PoC payloads for extracting database information and executing arbitrary SQL queries. It also includes path disclosure vectors.