CVE-2011-5168
banana_dance < 0.9 - SQL Injection via user.php id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2011-5168. PoCs published by Aodrulez.
AI-analyzed exploit summary This is a writeup describing an SQL injection vulnerability in Banana Dance CMS+Wiki. It provides details on the vulnerable parameter and error message but does not include functional exploit code.
Description
SQL injection vulnerability in user.php in Banana Dance before B.1.5 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Aodrulez · textwebappsphp
https://www.exploit-db.com/exploits/17919
This is a writeup describing an SQL injection vulnerability in Banana Dance CMS+Wiki. It provides details on the vulnerable parameter and error message but does not include functional exploit code.
Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target:
Banana Dance CMS+Wiki
No auth needed
Prerequisites:
access to the vulnerable web application
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026
Full analysis →
References (5)
Core 5
Core References
Exploit exploit
x_refsource_exploit-db
http://www.exploit-db.com/exploits/17919
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/83882
Vendor Advisory x_refsource_confirm
http://www.bananadance.org/Program-News/Minor-Update-and-New-Theme
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/49903
URL Repurposed x_refsource_confirm
http://www.doyoubananadance.com/Program-News/Important-Notice-About-SQLi-Exploit
Scores
EPSS
0.0112
EPSS Percentile
61.9%
Details
CWE
CWE-89
Status
published
Products (1)
bananadance/banana_dance
< 0.9
Published
Sep 15, 2012
Tracked Since
Feb 18, 2026