CVE-2012-5900
SAMEDIA LandShop 0.9.2 - SQL Injection via OB_ID, AREA_ID, or start Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-5900. PoCs published by Vulnerability-Lab.
AI-analyzed exploit summary The document describes multiple vulnerabilities in Landshop v0.9.2, including SQL injection and persistent XSS. It provides proof-of-concept URLs for SQL injection but lacks executable exploit code.
Description
Multiple SQL injection vulnerabilities in SAMEDIA LandShop 0.9.2 allow remote attackers to execute arbitrary SQL commands via the (1) OB_ID parameter in a single action to admin/action/objects.php, (2) AREA_ID parameter in a single action to admin/action/areas.php, or (3) start parameter in a show action to admin/action/pdf.php.
Exploits (1)
The document describes multiple vulnerabilities in Landshop v0.9.2, including SQL injection and persistent XSS. It provides proof-of-concept URLs for SQL injection but lacks executable exploit code.