Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-4436. PoCs published by R3d-D3V!L.
AI-analyzed exploit summary This is a writeup describing a blind SQL injection vulnerability in eWebquiz v8. It provides example URLs to test for the vulnerability but does not include functional exploit code.
Description
Multiple SQL injection vulnerabilities in Active Web Softwares eWebquiz 8 allow remote attackers to execute arbitrary SQL commands via the QuizID parameter to (1) questions.asp, (2) importquestions.asp, and (3) quiztakers.asp, different vectors than CVE-2007-1706.
Exploits (1)
This is a writeup describing a blind SQL injection vulnerability in eWebquiz v8. It provides example URLs to test for the vulnerability but does not include functional exploit code.