CVE-2010-5317

SweetRice CMS <0.6.7.1 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2010-5317.

AI-analyzed exploit summary The exploit demonstrates a logic error in SweetRice CMS 0.6.7 allowing an attacker to reset the admin password via a crafted POST request. It also includes PoCs for XSS and SQL injection vulnerabilities in the same software.

Description

Multiple SQL injection vulnerabilities in index.php in SweetRice CMS before 0.6.7.1 allow remote attackers to execute arbitrary SQL commands via (1) the file_name parameter in an attachment action, (2) the post parameter in a show_comment action, (3) the sys-name parameter in an rssfeed action, or (4) the sys-name parameter in a view action.

Exploits (1)

exploitdb WORKING POC
webappsphp
https://www.exploit-db.com/exploits/15413

The exploit demonstrates a logic error in SweetRice CMS 0.6.7 allowing an attacker to reset the admin password via a crafted POST request. It also includes PoCs for XSS and SQL injection vulnerabilities in the same software.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: SweetRice CMS 0.6.7
No auth needed
Prerequisites: knowledge of admin email address
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

EPSS 0.0120
EPSS Percentile 64.2%

Details

CWE
CWE-89
Status published
Products (1)
basic-cms/sweetrice 0.6.7.1
Published Jan 03, 2015
Tracked Since Feb 18, 2026