Exploitation Summary
EIP tracks 7 public exploits for CVE-2005-1633. PoCs published by [email protected].
AI-analyzed exploit summary The provided text describes SQL injection and XSS vulnerabilities in JGS-Portal, with an example URL demonstrating the SQL injection vector. It lacks executable exploit code but provides technical details about the vulnerabilities.
Description
Multiple SQL injection vulnerabilities in JGS-XA JGS-Portal 3.0.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) anzahl_beitraege parameter to jgs_portal.php, 2) year parameter to (jgs_portal_statistik.php, 3) year parameter to (jgs_portal_beitraggraf.php, 4) tag parameter to (jgs_portal_viewsgraf.php, 5) year parameter to (jgs_portal_themengraf.php, 6) year parameter to (jgs_portal_mitgraf.php, 7) id parameter to jgs_portal_sponsor.php, or (8) the Accept-Language header to jgs_portal_log.php.
Exploits (7)
The provided text describes SQL injection and XSS vulnerabilities in JGS-Portal, with an example URL demonstrating the SQL injection vector. It lacks executable exploit code but provides technical details about the vulnerabilities.
The provided text describes SQL injection and XSS vulnerabilities in JGS-Portal due to improper input sanitization. It includes a sample URL demonstrating the SQL injection vector but lacks executable exploit code.
The provided text describes SQL injection and XSS vulnerabilities in JGS-Portal, with example URLs demonstrating unsanitized input in the 'month' and 'year' parameters. No actual exploit code is present.
The provided text describes SQL injection and XSS vulnerabilities in JGS-Portal but does not include functional exploit code. It references a generic example URL for SQL injection without implementation details.
The provided text describes SQL injection and XSS vulnerabilities in JGS-Portal due to insufficient input sanitization. It includes a sample URL demonstrating the SQL injection vector but lacks executable exploit code.
The provided text describes SQL injection and XSS vulnerabilities in JGS-Portal due to improper input sanitization. It includes an example URL demonstrating the SQL injection vector but lacks executable exploit code.
The provided text describes SQL injection and XSS vulnerabilities in JGS-Portal but does not include actual exploit code. It references a generic example URL for SQL injection without technical details or payloads.