Exploitation Summary
EIP tracks 1 public exploit for CVE-2012-2925. PoCs published by loneferret.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Simple PHP Agenda 2.2.8 via the 'priority' parameter in the 'addTodo' action. The PoC includes payloads to extract user credentials, database names, and system files.
Description
SQL injection vulnerability in engine.php in Simple PHP Agenda 2.2.8 allows remote attackers to execute arbitrary SQL commands via the priority parameter in an addTodo action.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Simple PHP Agenda 2.2.8 via the 'priority' parameter in the 'addTodo' action. The PoC includes payloads to extract user credentials, database names, and system files.