CVE-2014-100020
iTechClassifieds 3.03.057 - SQL Injection via ChangeEmail.php PreviewNum Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-100020. PoCs published by vinicius777.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in iTechClassifieds v3.03.057 via the 'PreviewNum' and 'CatID' parameters. The PoC provides URLs with injection points but no payload details.
Description
SQL injection vulnerability in ChangeEmail.php in iTechClassifieds 3.03.057 allows remote attackers to execute arbitrary SQL commands via the PreviewNum parameter. NOTE: the CatID parameter is already covered by CVE-2008-0685.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in iTechClassifieds v3.03.057 via the 'PreviewNum' and 'CatID' parameters. The PoC provides URLs with injection points but no payload details.