CVE-2015-6009

Web Reference Database <0.9.6 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-6009. PoCs published by Mohab Ali.

AI-analyzed exploit summary The exploit demonstrates SQL injection and RCE vulnerabilities in Refbase <= 0.9.6. It includes PoC payloads for SQLi via the 'where' parameter in rss.php and RCE via the 'pathToMYSQL' parameter in install.php on Windows systems.

Description

Multiple SQL injection vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to execute arbitrary SQL commands via (1) the where parameter to rss.php or (2) the sqlQuery parameter to search.php, a different issue than CVE-2015-7382.

Exploits (1)

exploitdb WORKING POC
by Mohab Ali · textwebappsphp
https://www.exploit-db.com/exploits/38292

The exploit demonstrates SQL injection and RCE vulnerabilities in Refbase <= 0.9.6. It includes PoC payloads for SQLi via the 'where' parameter in rss.php and RCE via the 'pathToMYSQL' parameter in install.php on Windows systems.

Classification
Working Poc 100%
Attack Type
Sqli | Rce
Complexity
Moderate
Reliability
Reliable
Target: Refbase <= 0.9.6
No auth needed
Prerequisites: Access to the target application · MySQL credentials for RCE exploit
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/38292/
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/374092

Scores

EPSS 0.0153
EPSS Percentile 71.6%

Details

CWE
CWE-89
Status published
Products (1)
refbase/refbase < 0.9.6
Published Sep 28, 2015
Tracked Since Feb 18, 2026