CVE-2010-4856

xWeblog 2.2 - SQL Injection via arsiv.asp tarih Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-4856. PoCs published by ZoRLu.

AI-analyzed exploit summary This Python script exploits a SQL injection vulnerability in xWeblog v2.2 via the 'arsiv.asp' page's 'tarih' parameter to extract user credentials (AD and SIFRE) from the 'uyeler' table. It constructs malicious SQL queries and parses the response to display the extracted data.

Description

SQL injection vulnerability in arsiv.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the tarih parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by ZoRLu · pythonwebappsasp
https://www.exploit-db.com/exploits/15219

This Python script exploits a SQL injection vulnerability in xWeblog v2.2 via the 'arsiv.asp' page's 'tarih' parameter to extract user credentials (AD and SIFRE) from the 'uyeler' table. It constructs malicious SQL queries and parses the response to display the extracted data.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: xWeblog v2.2
No auth needed
Prerequisites: Target URL with vulnerable 'arsiv.asp' page
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/15219

Scores

EPSS 0.0092
EPSS Percentile 55.7%

Details

CWE
CWE-89
Status published
Products (1)
aspindir/xweblog 2.2
Published Oct 05, 2011
Tracked Since Feb 18, 2026