CVE-2011-5259
OrangeHRM < 2.6.11.2 - SQL Injection via CentralController id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2011-5259. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in OrangeHRM 2.6.11 via the 'id' parameter in the centralcontroller.php script. The PoC uses a UNION-based SQLi to extract database version and user information.
Description
SQL injection vulnerability in lib/controllers/CentralController.php in OrangeHRM before 2.6.11.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Exploits (1)
This exploit demonstrates an SQL injection vulnerability in OrangeHRM 2.6.11 via the 'id' parameter in the centralcontroller.php script. The PoC uses a UNION-based SQLi to extract database version and user information.