CVE-2012-3839
MyClientBase 0.12 - SQL Injection via Invoice Search Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-3839. PoCs published by Vulnerability-Lab.
AI-analyzed exploit summary The document describes multiple SQL injection vulnerabilities in MyClientBase v0.12, specifically in the invoice and tag search functionality. It includes error logs and details of the exploitation technique but does not contain executable exploit code.
Description
Multiple SQL injection vulnerabilities in application/core/MY_Model.php in MyClientBase 0.12 allow remote attackers to execute arbitrary SQL commands via the (1) invoice_number or (2) tags parameter to index.php/invoice_search.
Exploits (1)
The document describes multiple SQL injection vulnerabilities in MyClientBase v0.12, specifically in the invoice and tag search functionality. It includes error logs and details of the exploitation technique but does not contain executable exploit code.