Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-4569. PoCs published by SadHaCkEr.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in elkagroup software, allowing an attacker to extract user credentials via a UNION-based attack. The PoC provides a specific payload to dump usernames and passwords from the 'cm_user' table.
Description
SQL injection vulnerability in elkagroup Image Gallery allows remote attackers to execute arbitrary SQL commands via the id parameter to the default URI under news/.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in elkagroup software, allowing an attacker to extract user credentials via a UNION-based attack. The PoC provides a specific payload to dump usernames and passwords from the 'cm_user' table.