CVE-2012-1670
PHP Grade Book < 1.9.5 BETA - Unauthenticated Database Exposure via SaveSQL Action
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-1670. PoCs published by Mark Stanislav.
AI-analyzed exploit summary This exploit leverages an unauthenticated SQL database export vulnerability in PHP Grade Book 1.9.4 by accessing the 'Database Backup' method directly via a crafted URL. It also allows session hijacking by passing stolen credentials via cookies.
Description
admin/index.php in PHP Grade Book before 1.9.5 BETA allows remote attackers to read the database via a SaveSQL action.
Exploits (1)
This exploit leverages an unauthenticated SQL database export vulnerability in PHP Grade Book 1.9.4 by accessing the 'Database Backup' method directly via a crafted URL. It also allows session hijacking by passing stolen credentials via cookies.