CVE-2011-5183
OrderSys <= 1.6.4 - SQL Injection via where_clause Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2011-5183. PoCs published by muuratsalo.
AI-analyzed exploit summary The document describes SQL injection vulnerabilities in OrderSys <= 1.6.4, providing URLs with injection points but no actual exploit code. It outlines the disclosure timeline and affected endpoints.
Description
Multiple SQL injection vulnerabilities in OrderSys 1.6.4 and earlier allow remote attackers to execute arbitrary SQL commands via the where_clause parameter to (1) index.php, (2) index_long.php, or (3) index_short.php in ordering/interface_creator/.
Exploits (1)
The document describes SQL injection vulnerabilities in OrderSys <= 1.6.4, providing URLs with injection points but no actual exploit code. It outlines the disclosure timeline and affected endpoints.