CVE-2009-4595
PHP Inventory 1.2 - Authenticated SQL Injection via sup_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4595.
AI-analyzed exploit summary The document describes an authentication bypass and SQL injection vulnerability in PHP Inventory v1.2, including example payloads for SQLi and reflected XSS. It provides technical details on how to exploit the flaws but does not include functional exploit code.
Description
SQL injection vulnerability in index.php in PHP Inventory 1.2 allows remote authenticated users to execute arbitrary SQL commands via the sup_id parameter in a suppliers details action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
Exploits (1)
The document describes an authentication bypass and SQL injection vulnerability in PHP Inventory v1.2, including example payloads for SQLi and reflected XSS. It provides technical details on how to exploit the flaws but does not include functional exploit code.