Exploitation Summary
EIP tracks 1 public exploit for CVE-2009-4936. PoCs published by YEnH4ckEr.
AI-analyzed exploit summary This exploit demonstrates multiple SQL injection vulnerabilities in Small Pirates CMS v2.1, including union-based SQLi and blind SQLi, as well as a cookie stealing vulnerability via XSS. The PoC provides specific URLs and payloads to exploit these vulnerabilities.
Description
Multiple SQL injection vulnerabilities in Small Pirate (SPirate) 2.1 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to the default URI in an rss .xml action, or the id parameter to (2) pag1.php, (3) pag1-guest.php, (4) rss-comment_post.php (aka rss-coment_post.php), or (5) rss-pic-comment.php.
Exploits (1)
This exploit demonstrates multiple SQL injection vulnerabilities in Small Pirates CMS v2.1, including union-based SQLi and blind SQLi, as well as a cookie stealing vulnerability via XSS. The PoC provides specific URLs and payloads to exploit these vulnerabilities.