CVE-2009-4985
Accessories Me PHP Affiliate Script 1.4 - SQL Injection via Go Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4985. PoCs published by Moudi.
AI-analyzed exploit summary The exploit demonstrates XSS and blind SQL injection vulnerabilities in AccessoriesMe PHP Affiliate Script v1.4. It provides functional PoC URLs for both XSS (via 'Keywords' and 'SearchIndex' parameters) and blind SQLi (via 'Go' parameter in browse.php).
Description
SQL injection vulnerability in browse.php in Accessories Me PHP Affiliate Script 1.4 allows remote attackers to execute arbitrary SQL commands via the Go parameter.
Exploits (1)
The exploit demonstrates XSS and blind SQL injection vulnerabilities in AccessoriesMe PHP Affiliate Script v1.4. It provides functional PoC URLs for both XSS (via 'Keywords' and 'SearchIndex' parameters) and blind SQLi (via 'Go' parameter in browse.php).