CVE-2010-4969

BrotherScripts Business Directory - SQL Injection via articlesdetails.php id Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-4969. PoCs published by Easy Laster.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in BS Business Directory via the 'id' parameter in articlesdetails.php. The PoC uses a UNION-based SQLi to extract user credentials from the fpoll_config table.

Description

SQL injection vulnerability in articlesdetails.php in BrotherScripts (BS) Business Directory allows remote attackers to execute arbitrary SQL commands via the id parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Easy Laster · textwebappsphp
https://www.exploit-db.com/exploits/14241

This exploit demonstrates a SQL injection vulnerability in BS Business Directory via the 'id' parameter in articlesdetails.php. The PoC uses a UNION-based SQLi to extract user credentials from the fpoll_config table.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: BS Business Directory (version unspecified)
No auth needed
Prerequisites: Target must be running BS Business Directory with vulnerable articlesdetails.php endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/14241

Scores

EPSS 0.0095
EPSS Percentile 56.5%

Details

CWE
CWE-89
Status published
Products (1)
brotherscripts/business_directory
Published Nov 01, 2011
Tracked Since Feb 18, 2026