CVE-2009-4807
Graugon PHP Article Publisher 1.0 - SQL Injection via c or id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4807. PoCs published by x0r.
AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in Graugon PHP Article Publisher 1.0 via the 'c' and 'id' parameters, as well as insecure cookie handling for authentication bypass. The PoC includes URLs to extract sensitive data from the database and a JavaScript snippet to set an admin cookie.
Description
Multiple SQL injection vulnerabilities in Graugon PHP Article Publisher 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) c parameter to index.php and the (2) id parameter to view.php.
Exploits (1)
The exploit demonstrates SQL injection vulnerabilities in Graugon PHP Article Publisher 1.0 via the 'c' and 'id' parameters, as well as insecure cookie handling for authentication bypass. The PoC includes URLs to extract sensitive data from the database and a JavaScript snippet to set an admin cookie.