9154exploit
http://www.exploit-db.com/exploits/9154 CVE-2009-4564
ZenPhoto 1.2.5 - Completely Blind SQL Injection
Record summary
CVE-2009-4564 has a selected CVSS score of 6.8; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in index.php in Zenphoto 1.2.5, when the ZenPage plugin is enabled, allows remote attackers to execute arbitrary SQL commands via the category parameter, related to a URI under news/category/.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBZenPhoto 1.2.5 - Completely Blind SQL InjectionExploitDB exploitby petrosNot analyzed1 file
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2009-4564