CVE-2009-4936
Last modified
CVE-2009-4936 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in Small Pirate (SPirate) 2.1 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to the default URI in an rss .xml action, or the id parameter to (2) pag1.php, (3) pag1-guest.php, (4) rss-comment_post.php (aka rss-coment_post.php), or (5) rss-pic-comment.php.. EPSS estimates a 1.83% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in Small Pirate (SPirate) 2.1 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to the default URI in an rss .xml action, or the id parameter to (2) pag1.php, (3) pag1-guest.php, (4) rss-comment_post.php (aka rss-coment_post.php), or (5) rss-pic-comment.php.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Spirate | Small Pirate | 2.1 |
References
- http://osvdb.org/54785Exploit
- http://osvdb.org/54786Exploit
- http://osvdb.org/54787Exploit
- http://osvdb.org/54788Exploit
- http://secunia.com/advisories/35272Vendor Advisory
- http://osvdb.org/54785Exploit
- http://osvdb.org/54786Exploit
- http://osvdb.org/54787Exploit
- http://osvdb.org/54788Exploit
- http://secunia.com/advisories/35272Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-4936?
How severe is CVE-2009-4936?
How do I fix CVE-2009-4936?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-4930Cross-site scripting (XSS) vulnerability in the twbkwbis.P_S…
- CVE-2009-4931Stack-based buffer overflow in Groovy Media Player 1.1.0 all…
- CVE-2009-4932Stack-based buffer overflow in 1by1 1.67 (aka 1.6.7.0) allow…
- CVE-2009-4933Multiple SQL injection vulnerabilities in login.php in EZ We…
- CVE-2009-4934Cross-site scripting (XSS) vulnerability in index.php in Onl…
- CVE-2009-4935SQL injection vulnerability in ogp_show.php in Online Guestb…
- CVE-2009-4937Cross-site scripting (XSS) vulnerability in Small Pirate (SP…
- CVE-2009-4938SQL injection vulnerability in the JVideo! (com_jvideo) comp…
- CVE-2009-4939Multiple cross-site scripting (XSS) vulnerabilities in index…
- CVE-2009-4940SQL injection vulnerability in index.php in Zeus Cart 2.3 an…
- CVE-2009-4941Cross-site scripting (XSS) vulnerability in sign_in.php in A…
- CVE-2009-4942Cross-site request forgery (CSRF) vulnerability in ACollab 1…
Are you affected by CVE-2009-4936?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
