CVE-2009-4208
Open-school 1.0 - SQL Injection via os_news Module id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4208. PoCs published by OzX.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Open-school CMS 1.0 via the 'id' parameter in index.php. It provides specific payloads to extract admin, student, and teacher credentials from the database.
Description
SQL injection vulnerability in the os_news module in Open-school (OS) 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a show action to index.php.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Open-school CMS 1.0 via the 'id' parameter in index.php. It provides specific payloads to extract admin, student, and teacher credentials from the database.