CVE-2010-1364

Uiga Personal Portal - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2010-1364. PoCs published by Easy Laster, 41.w4r10r.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Uiga Personal Portal's index.php. The PoC provides a crafted URL that extracts admin credentials via a UNION-based SQLi attack.

Description

SQL injection vulnerability in index.php in Uiga Personal Portal, as downloaded on 20100301, allows remote attackers to execute arbitrary SQL commands via the id parameter in a photos action. NOTE: some of these details are obtained from third party information.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Easy Laster · textwebappsphp
https://www.exploit-db.com/exploits/11599

This exploit demonstrates a SQL injection vulnerability in Uiga Personal Portal's index.php. The PoC provides a crafted URL that extracts admin credentials via a UNION-based SQLi attack.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Uiga Personal Portal
No auth needed
Prerequisites: Target running Uiga Personal Portal with vulnerable index.php endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
by 41.w4r10r · textwebappsphp
https://www.exploit-db.com/exploits/12399

This exploit demonstrates a SQL injection vulnerability in Uiga Personal Portal's index.php via the 'view' and 'exhort' parameters. It allows an attacker to extract sensitive information such as admin credentials from the database.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Uiga Personal Portal (Web Application)
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0488
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/38757
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/11599

Scores

EPSS 0.0098
EPSS Percentile 57.6%

Details

CWE
CWE-89
Status published
Products (1)
uiga/personal_portal
Published Apr 13, 2010
Tracked Since Feb 18, 2026