CVE-2012-5685
ZPanel < 10.0.1 - SQL Injection via inEmailAddress Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-5685. PoCs published by pcsjj.
AI-analyzed exploit summary This exploit demonstrates multiple vulnerabilities in ZPanel <= 10.0.1, including CSRF, XSS, SQL injection, and a password reset weakness. It provides detailed HTTP requests to exploit these flaws, such as creating FTP users, injecting malicious scripts, and manipulating database content.
Description
SQL injection vulnerability in ZPanel 10.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the inEmailAddress parameter in an UpdateClient action in the manage_clients module to the default URI.
Exploits (1)
This exploit demonstrates multiple vulnerabilities in ZPanel <= 10.0.1, including CSRF, XSS, SQL injection, and a password reset weakness. It provides detailed HTTP requests to exploit these flaws, such as creating FTP users, injecting malicious scripts, and manipulating database content.