Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-4792. PoCs published by SirGod.
AI-analyzed exploit summary The exploit demonstrates SQL injection and arbitrary file upload vulnerabilities in BandSite CMS 1.1.4. The SQLi allows credential extraction via UNION-based attacks, while the upload flaw permits shell deployment as an admin.
Description
SQL injection vulnerability in includes/content/member_content.php in BandSite CMS 1.1.4 allows remote attackers to execute arbitrary SQL commands via the memid parameter to members.php.
Exploits (1)
The exploit demonstrates SQL injection and arbitrary file upload vulnerabilities in BandSite CMS 1.1.4. The SQLi allows credential extraction via UNION-based attacks, while the upload flaw permits shell deployment as an admin.