CVE-2009-4698
XOOPS Celepar Qas Module - SQL Injection via codigo or cod_categoria Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2009-4698. PoCs published by Moudi, s4r4d0.
AI-analyzed exploit summary This is a writeup detailing multiple vulnerabilities (Blind SQL Injection and XSS) in the Xoops Celepar Module Qas. It provides example URLs demonstrating the vulnerabilities but does not include executable exploit code.
Description
Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute arbitrary SQL commands via the codigo parameter to (1) aviso.php and (2) imprimir.php, and the (3) cod_categoria parameter to categoria.php.
Exploits (2)
This is a writeup detailing multiple vulnerabilities (Blind SQL Injection and XSS) in the Xoops Celepar Module Qas. It provides example URLs demonstrating the vulnerabilities but does not include executable exploit code.
This exploit demonstrates a SQL injection vulnerability in the Xoops Celepar module's Aviso.php file, allowing attackers to extract data from the database via crafted input in the 'codigo' parameter.