Exploitation Summary
EIP tracks 1 public exploit for CVE-2010-5317.
AI-analyzed exploit summary The exploit demonstrates a logic error in SweetRice CMS 0.6.7 allowing an attacker to reset the admin password via a crafted POST request. It also includes PoCs for XSS and SQL injection vulnerabilities in the same software.
Description
Multiple SQL injection vulnerabilities in index.php in SweetRice CMS before 0.6.7.1 allow remote attackers to execute arbitrary SQL commands via (1) the file_name parameter in an attachment action, (2) the post parameter in a show_comment action, (3) the sys-name parameter in an rssfeed action, or (4) the sys-name parameter in a view action.
Exploits (1)
The exploit demonstrates a logic error in SweetRice CMS 0.6.7 allowing an attacker to reset the admin password via a crafted POST request. It also includes PoCs for XSS and SQL injection vulnerabilities in the same software.