Exploitation Summary
EIP tracks 1 public exploit for CVE-2013-5120. PoCs published by Matias Fontanini.
AI-analyzed exploit summary The document describes SQL injection vulnerabilities in PHPFox v3.6.0 (build3), specifically in the 'search[gender]' and 'search[sort_by]' parameters. It provides proof-of-concept POST requests demonstrating blind SQL injection and time-based exploitation techniques.
Description
SQL injection vulnerability in PHPFox before 3.6.0 (build4) allows remote attackers to execute arbitrary SQL commands via the search[gender] parameter to user/browse/view_/.
Exploits (1)
The document describes SQL injection vulnerabilities in PHPFox v3.6.0 (build3), specifically in the 'search[gender]' and 'search[sort_by]' parameters. It provides proof-of-concept POST requests demonstrating blind SQL injection and time-based exploitation techniques.