CVE-2009-5090
Bloggeruniverse Beta 2 - SQL Injection via editcomments.php id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-5090. PoCs published by Osirys.
AI-analyzed exploit summary This Perl script exploits SQL injection in Bloggeruniverse v2Beta via the 'editcomments.php' endpoint to extract admin credentials, disclose files, and execute remote commands by writing a PHP shell.
Description
SQL injection vulnerability in editcomments.php in Bloggeruniverse Beta 2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter and possibly other unspecified vectors.
Exploits (1)
This Perl script exploits SQL injection in Bloggeruniverse v2Beta via the 'editcomments.php' endpoint to extract admin credentials, disclose files, and execute remote commands by writing a PHP shell.