CVE-2009-4155

Eshopbuilde CMS - SQL Injection

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in Eshopbuilde CMS allow remote attackers to execute arbitrary SQL commands via the sitebid parameter to (1) home-f.asp and (2) opinions-f.asp; (3) sitebid, (4) id, (5) secText, (6) client-ip, and (7) G_id parameters to more-f.asp; (8) sitebid, (9) id, (10) ma_id, (11) mi_id, (12) secText, (13) client-ip, and (14) G_id parameters to selectintro.asp; (15) sitebid, (16) secText, (17) adv_code, and (18) client-ip parameters to advcount.asp; (19) sitebid, (20) secText, (21) Grp_Code, (22) _method, and (23) client-ip parameters to advview.asp; and (24) sitebid, (25) secText, (26) newsId, and (27) client-ip parameters to dis_new-f.asp.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Isfahan · textwebappsasp
https://www.exploit-db.com/exploits/10253

References (1)

Core 1
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/508137/100/0/threaded

Scores

EPSS 0.0027
EPSS Percentile 50.5%

Details

CWE
CWE-89
Status published
Products (1)
eshopbuilder/eshopbuilde_cms
Published Dec 02, 2009
Tracked Since Feb 18, 2026