Exploitation Summary
EIP tracks 1 public exploit for CVE-2004-1519.
AI-analyzed exploit summary This advisory details multiple SQL injection, XSS, and CSRF vulnerabilities in phpBugTracker v1.6.0, including specific attack vectors and proof-of-concept URLs. It also references CVE-2004-1519, which remains unpatched in this version.
Description
SQL injection vulnerability in bug.php in phpBugTracker 0.9.1 allows remote attackers to execute arbitrary SQL commands via (1) the bug_id parameter in a viewvotes operation or (2) the project parameter in an add operation.
Exploits (1)
This advisory details multiple SQL injection, XSS, and CSRF vulnerabilities in phpBugTracker v1.6.0, including specific attack vectors and proof-of-concept URLs. It also references CVE-2004-1519, which remains unpatched in this version.