CVE-2009-1812
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 0.9%
exploitation probability
0.9%top 44% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Multiple SQL injection vulnerabilities in myGesuad 0.9.14 (aka 0.9) allow remote attackers to execute arbitrary SQL commands via (1) the formUser parameter (aka the Name field) to common/login.php, and allow remote authenticated users to execute arbitrary SQL commands via the ID parameter in a Detail action to (2) kategorie.php, (3) budget.php, (4) zahlung.php, or (5) adresse.php in modules/, related to classes/class.perform.php.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
cve_reference✓ VexDay Proofwww.exploit-db.com/exploits/8708⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.