CVE-2011-5230

Seotoaster < 1.9 - SQL Injection via Login or Member Login Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-5230. PoCs published by Stefan Schurtz.

AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in Seotoaster v1.9, allowing an attacker to bypass admin authentication by injecting a malicious payload into the username field. The PoC provides a simple URL and credentials to achieve unauthorized access.

Description

Multiple SQL injection vulnerabilities in the selectUserIdByLoginPass function in seotoaster_core/application/models/LoginModel.php in Seotoaster 1.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) login parameter to sys/login/index or (2) memberLoginName parameter to sys/login/member.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Stefan Schurtz · textwebappsphp
https://www.exploit-db.com/exploits/18246

This exploit demonstrates an SQL injection vulnerability in Seotoaster v1.9, allowing an attacker to bypass admin authentication by injecting a malicious payload into the username field. The PoC provides a simple URL and credentials to achieve unauthorized access.

Classification
Working Poc 100%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Seotoaster v1.9
No auth needed
Prerequisites: Access to the login page of the target application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/77736
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/71843
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/46881
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18246

Scores

EPSS 0.0224
EPSS Percentile 80.5%

Details

CWE
CWE-89
Status published
Products (3)
seotoaster/seotoaster 1.8.2
seotoaster/seotoaster 1.8.3
seotoaster/seotoaster < 1.9
Published Oct 25, 2012
Tracked Since Feb 18, 2026