CVE-2009-5094
CMS Faethon 2.2.0 Ultimate - SQL Injection via info.php item Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-5094. PoCs published by Osirys.
AI-analyzed exploit summary This Perl script exploits a SQL injection vulnerability in CmsFaethon 2.2.0 Ultimate to extract admin credentials and achieve remote code execution by writing a PHP shell via MySQL's INTO DUMPFILE function. It automates the discovery of the web root path by leveraging error logs.
Description
SQL injection vulnerability in info.php in CMS Faethon 2.2.0 Ultimate allows remote attackers to execute arbitrary SQL commands via the item parameter.
Exploits (1)
This Perl script exploits a SQL injection vulnerability in CmsFaethon 2.2.0 Ultimate to extract admin credentials and achieve remote code execution by writing a PHP shell via MySQL's INTO DUMPFILE function. It automates the discovery of the web root path by leveraging error logs.