CVE-2012-5865
Achievo 1.4.5 - Authenticated SQL Injection via Activity ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-5865. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary The advisory details two vulnerabilities in Achievo 1.4.5: an SQL injection via the 'activityid' parameter in 'dispatch.php' and a cross-site scripting (XSS) flaw in 'include.php' via the 'field' parameter. Both vulnerabilities are described with proof-of-concept URLs but no executable exploit code is provided.
Description
SQL injection vulnerability in dispatch.php in Achievo 1.4.5 allows remote authenticated users to execute arbitrary SQL commands via the activityid parameter in a stats action.
Exploits (1)
The advisory details two vulnerabilities in Achievo 1.4.5: an SQL injection via the 'activityid' parameter in 'dispatch.php' and a cross-site scripting (XSS) flaw in 'include.php' via the 'field' parameter. Both vulnerabilities are described with proof-of-concept URLs but no executable exploit code is provided.