CVE-2013-5117
zldnn dnnarticle < 10.0 - SQL Injection via categoryid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-5117. PoCs published by Sajjad Pourali.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in the DNNArticle module for DotNetNuke. The PoC uses a crafted URL to inject a SQL query that retrieves the database version, confirming the vulnerability.
Description
SQL injection vulnerability in the RSS page (DNNArticleRSS.aspx) in the ZLDNN DNNArticle module before 10.1 for DotNetNuke allows remote attackers to execute arbitrary SQL commands via the categoryid parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in the DNNArticle module for DotNetNuke. The PoC uses a crafted URL to inject a SQL query that retrieves the database version, confirming the vulnerability.