CVE-2010-4357

SiteEngine 7.1 - SQL Injection via Module Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-4357. PoCs published by Beach.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in SiteEngine 7.1, allowing an attacker to extract user credentials from the database via union-based SQLi. It also describes a method to upload a backdoor through the administrator panel.

Description

SQL injection vulnerability in comments.php in SiteEngine 7.1 allows remote attackers to execute arbitrary SQL commands via the module parameter.

Exploits (1)

exploitdb WORKING POC
by Beach · textwebappsphp
https://www.exploit-db.com/exploits/15612

This exploit demonstrates a SQL injection vulnerability in SiteEngine 7.1, allowing an attacker to extract user credentials from the database via union-based SQLi. It also describes a method to upload a backdoor through the administrator panel.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: SiteEngine 7.1
No auth needed
Prerequisites: Comments feature must be enabled (default setting) · Target must be running SiteEngine 7.1
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/15612
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/45056
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42353

Scores

EPSS 0.0098
EPSS Percentile 57.8%

Details

CWE
CWE-89
Status published
Products (1)
boka/siteengine 7.1
Published Dec 01, 2010
Tracked Since Feb 18, 2026