CVE-2010-2511

2daybiz Multi Level Marketing Software - SQL Injection via viewnews.php nwsid Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-2511. PoCs published by JaMbA.

AI-analyzed exploit summary The provided text describes an SQL injection vulnerability in viewnews.php for CVE-2010-2511, with a basic example URL but no functional exploit code. It lacks technical depth and executable payloads.

Description

SQL injection vulnerability in viewnews.php in 2daybiz Multi Level Marketing (MLM) Software allows remote attackers to execute arbitrary SQL commands via the nwsid parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by JaMbA · textwebappsphp
https://www.exploit-db.com/exploits/14005

The provided text describes an SQL injection vulnerability in viewnews.php for CVE-2010-2511, with a basic example URL but no functional exploit code. It lacks technical depth and executable payloads.

Classification
Writeup 80%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target: 2daybiz MLM Script (version unspecified)
No auth needed
Prerequisites: Access to the vulnerable viewnews.php endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/14005
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/40340
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/41097

Scores

EPSS 0.0096
EPSS Percentile 56.9%

Details

CWE
CWE-89
Status published
Products (1)
2daybiz/multi_level_marketing_software
Published Jun 28, 2010
Tracked Since Feb 18, 2026