CVE-2013-7189

iScripts AutoHoster - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2013-7189. PoCs published by i-Hmx.

AI-analyzed exploit summary The provided text describes a vulnerability in iScripts AutoHoster where insufficient sanitization of user-supplied data in the 'invno' parameter of 'payinvoiceothers.php' can lead to multiple security issues, including arbitrary command execution or script injection. However, no actual exploit code is included.

Description

Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary SQL commands via the cmbdomain parameter to (1) checktransferstatus.php, (2) checktransferstatusbck.php, or (3) additionalsettings.php; or (4) invno parameter to payinvoiceothers.php.

Exploits (4)

exploitdb WRITEUP VERIFIED
by i-Hmx · textwebappsphp
https://www.exploit-db.com/exploits/38888

The provided text describes a vulnerability in iScripts AutoHoster where insufficient sanitization of user-supplied data in the 'invno' parameter of 'payinvoiceothers.php' can lead to multiple security issues, including arbitrary command execution or script injection. However, no actual exploit code is included.

Classification
Writeup 80%
Attack Type
Sqli | Xss | Other
Complexity
Trivial
Reliability
Theoretical
Target: iScripts AutoHoster
No auth needed
Prerequisites: Access to the vulnerable endpoint '/payinvoiceothers.php'
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by i-Hmx · textwebappsphp
https://www.exploit-db.com/exploits/38886

This exploit demonstrates SQL injection vulnerabilities in iScripts AutoHoster via the 'checktransferstatusbck.php' endpoint. It includes payloads to extract table names, staff count, and sensitive staff data (passwords, logins, emails) using UNION-based SQLi with MySQL-specific techniques.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: iScripts AutoHoster
No auth needed
Prerequisites: Access to the vulnerable endpoint · MySQL database backend
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by i-Hmx · textwebappsphp
https://www.exploit-db.com/exploits/38885

This exploit demonstrates SQL injection vulnerabilities in iScripts AutoHoster via the `checktransferstatus.php` endpoint. It includes payloads to extract table names, staff counts, and sensitive staff data (passwords, logins, emails) using UNION-based SQLi with MySQL-specific syntax.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: iScripts AutoHoster
No auth needed
Prerequisites: Access to the vulnerable endpoint · MySQL database backend
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP VERIFIED
by i-Hmx · textwebappsphp
https://www.exploit-db.com/exploits/38887

The provided text describes a time-based blind SQL injection vulnerability in iScripts AutoHoster via the /additionalsettings.php endpoint. The POST parameter 'cmbdomain' is identified as the injection point, but no actual exploit code is included.

Classification
Writeup 80%
Attack Type
Sqli
Complexity
Moderate
Reliability
Theoretical
Target: iScripts AutoHoster
No auth needed
Prerequisites: Access to the /additionalsettings.php endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/101049
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/89816
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2013/Dec/121
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/101050
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/101051
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/101053

Scores

EPSS 0.0135
EPSS Percentile 68.0%

Details

CWE
CWE-89
Status published
Products (1)
iscripts/autohoster 2.4
Published Dec 20, 2013
Tracked Since Feb 18, 2026