CVE-2011-5116

SetSeed CMS < 5.11.2 - SQL Injection via loggedInUser Cookie

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2011-5116. PoCs published by LiquidWorm.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in SetSeed CMS 5.8.20 via the 'loggedInUser' cookie parameter. The proof-of-concept shows how an attacker can manipulate the cookie to trigger a SQL syntax error, confirming the vulnerability.

Description

SQL injection vulnerability in setseed-hub in SetSeed CMS 5.8.20, 5.11.2, and earlier allows remote attackers to execute arbitrary SQL commands via the loggedInUser cookie.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textwebappsphp
https://www.exploit-db.com/exploits/18065

This exploit demonstrates a SQL injection vulnerability in SetSeed CMS 5.8.20 via the 'loggedInUser' cookie parameter. The proof-of-concept shows how an attacker can manipulate the cookie to trigger a SQL syntax error, confirming the vulnerability.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: SetSeed CMS 5.8.20
No auth needed
Prerequisites: Access to the target application · Ability to send crafted HTTP requests
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18065

Scores

EPSS 0.0105
EPSS Percentile 59.8%

Details

CWE
CWE-89
Status published
Products (2)
setseed/setseed_cms 5.8.20
setseed/setseed_cms < 5.11.2
Published Aug 23, 2012
Tracked Since Feb 18, 2026