Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-4618. PoCs published by Mr.SQL.
AI-analyzed exploit summary This exploit demonstrates a remote SQL injection vulnerability in the 'aboutus.php' and 'faq.php' scripts of the Bus Script software. The vulnerability allows an attacker to extract user credentials via a UNION-based SQL injection.
Description
Multiple SQL injection vulnerabilities in Tourism Script Bus Script allow remote attackers to execute arbitrary SQL commands via the sitetext_id parameter to (1) aboutus.php and (2) faq.php.
Exploits (1)
This exploit demonstrates a remote SQL injection vulnerability in the 'aboutus.php' and 'faq.php' scripts of the Bus Script software. The vulnerability allows an attacker to extract user credentials via a UNION-based SQL injection.