CVE-2009-3806
dedecms 5.1 - SQL Injection via feedback_js.php arcurl Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3806. PoCs published by Securitylab Security Research.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in DEDECMS 5.1 via the `feedback_js.php` file. The PoC shows how an attacker can extract admin credentials by manipulating the `arcurl` parameter to inject a malicious SQL query.
Description
SQL injection vulnerability in feedback_js.php in DedeCMS 5.1 allows remote attackers to execute arbitrary SQL commands via the arcurl parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in DEDECMS 5.1 via the `feedback_js.php` file. The PoC shows how an attacker can extract admin credentials by manipulating the `arcurl` parameter to inject a malicious SQL query.