CVE-2013-3524
Pop Up News module 2.0 - SQL Injection via itemid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-3524. PoCs published by NoGe.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in phpVMS Virtual Airline Administration versions 2.1.934 and 2.1.935. The PoC shows how an attacker can inject malicious SQL queries via the 'itemid' parameter in the PopUpNews module to extract sensitive information such as database version, name, and user credentials.
Description
SQL injection vulnerability in popupnewsitem/ in the Pop Up News module 2.0 and possibly earlier for phpVMS allows remote attackers to execute arbitrary SQL commands via the itemid parameter. NOTE: this was originally reported as a problem in phpVMS.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in phpVMS Virtual Airline Administration versions 2.1.934 and 2.1.935. The PoC shows how an attacker can inject malicious SQL queries via the 'itemid' parameter in the PopUpNews module to extract sensitive information such as database version, name, and user credentials.