CVE-2011-5116
SetSeed CMS < 5.11.2 - SQL Injection via loggedInUser Cookie
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2011-5116. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in SetSeed CMS 5.8.20 via the 'loggedInUser' cookie parameter. The proof-of-concept shows how an attacker can manipulate the cookie to trigger a SQL syntax error, confirming the vulnerability.
Description
SQL injection vulnerability in setseed-hub in SetSeed CMS 5.8.20, 5.11.2, and earlier allows remote attackers to execute arbitrary SQL commands via the loggedInUser cookie.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in SetSeed CMS 5.8.20 via the 'loggedInUser' cookie parameter. The proof-of-concept shows how an attacker can manipulate the cookie to trigger a SQL syntax error, confirming the vulnerability.