CVE-2010-4969
BrotherScripts Business Directory - SQL Injection via articlesdetails.php id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-4969. PoCs published by Easy Laster.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in BS Business Directory via the 'id' parameter in articlesdetails.php. The PoC uses a UNION-based SQLi to extract user credentials from the fpoll_config table.
Description
SQL injection vulnerability in articlesdetails.php in BrotherScripts (BS) Business Directory allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Easy Laster · textwebappsphp
https://www.exploit-db.com/exploits/14241
This exploit demonstrates a SQL injection vulnerability in BS Business Directory via the 'id' parameter in articlesdetails.php. The PoC uses a UNION-based SQLi to extract user credentials from the fpoll_config table.
Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:
BS Business Directory (version unspecified)
No auth needed
Prerequisites:
Target must be running BS Business Directory with vulnerable articlesdetails.php endpoint
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (1)
Core 1
Core References
Exploit exploit
x_refsource_exploit-db
http://www.exploit-db.com/exploits/14241
Scores
EPSS
0.0095
EPSS Percentile
56.5%
Details
CWE
CWE-89
Status
published
Products (1)
brotherscripts/business_directory
Published
Nov 01, 2011
Tracked Since
Feb 18, 2026