Exploitation Summary
EIP tracks 1 public exploit for CVE-2013-2594. PoCs published by Joseph Sheridan.
AI-analyzed exploit summary The document describes a SQL injection vulnerability in Hornbill Supportworks ITSM's calldiary.php file, allowing attackers to execute arbitrary SQL commands and potentially write a PHP webshell to the webroot for full system control.
Description
SQL injection vulnerability in reports/calldiary.php in Hornbill Supportworks ITSM 1.0.0 through 3.4.14 allows remote attackers to execute arbitrary SQL commands via the callref parameter.
Exploits (1)
The document describes a SQL injection vulnerability in Hornbill Supportworks ITSM's calldiary.php file, allowing attackers to execute arbitrary SQL commands and potentially write a PHP webshell to the webroot for full system control.