CVE-2010-1744

B2B Gold Script - SQL Injection via id Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-1744. PoCs published by v3n0m.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in B2B Gold Script, allowing an attacker to extract admin credentials via a crafted SQL query. The PoC provides a specific payload and URL structure to exploit the vulnerability.

Description

SQL injection vulnerability in product.html in B2B Gold Script allows remote attackers to execute arbitrary SQL commands via the id parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by v3n0m · textwebappsphp
https://www.exploit-db.com/exploits/12460

This exploit demonstrates a SQL injection vulnerability in B2B Gold Script, allowing an attacker to extract admin credentials via a crafted SQL query. The PoC provides a specific payload and URL structure to exploit the vulnerability.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: B2B Gold Script
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/12460
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/58265
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/39830
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/64212
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39710

Scores

EPSS 0.0115
EPSS Percentile 62.8%

Details

CWE
CWE-89
Status published
Products (1)
alibabaclone/b2b_gold_script
Published May 06, 2010
Tracked Since Feb 18, 2026