CVE-2009-3970
PHP Dir Submit - Authenticated SQL Injection via aid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-3970. PoCs published by Mr.tro0oqy.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in PHP Dir Submit 1.00 via the 'aid' parameter. The PoC provides a step-by-step guide to exploit the vulnerability, including a crafted URL to extract database information such as version, user, and database name.
Description
SQL injection vulnerability in index.php in PHP Dir Submit (aka WebsiteSubmitter or Submitter Script) allows remote authenticated users to execute arbitrary SQL commands via the aid parameter in a showarticle action.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in PHP Dir Submit 1.00 via the 'aid' parameter. The PoC provides a step-by-step guide to exploit the vulnerability, including a crafted URL to extract database information such as version, user, and database name.