CVE-2010-4784

PHP Web Scripts Easy Banner Free <2009.05.18 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-4784. PoCs published by Aliaksandr Hartsuyeu.

AI-analyzed exploit summary This is a vulnerability writeup describing SQL injection and HTML injection flaws in Easy Banner Free 2009.05.18. It provides example payloads for authentication bypass via SQLi but does not include executable exploit code.

Description

Multiple SQL injection vulnerabilities in member.php in PHP Web Scripts Easy Banner Free 2009.05.18, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Aliaksandr Hartsuyeu · textwebappsphp
https://www.exploit-db.com/exploits/35016

This is a vulnerability writeup describing SQL injection and HTML injection flaws in Easy Banner Free 2009.05.18. It provides example payloads for authentication bypass via SQLi but does not include executable exploit code.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Easy Banner Free 2009.05.18
No auth needed
Prerequisites: Network access to the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Exploit x_refsource_misc
http://evuln.com/vulns/147/summary.html
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/45066
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/514908/100/0/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/42316
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/69511
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/8184

Scores

EPSS 0.0112
EPSS Percentile 61.8%

Details

CWE
CWE-89
Status published
Products (1)
phpwebscripts/easy_banner_free 2009.05.18
Published Apr 07, 2011
Tracked Since Feb 18, 2026