Exploitation Summary
EIP tracks 1 public exploit for CVE-2014-10023. PoCs published by AtT4CKxT3rR0r1ST.
AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in TopicsViewer v3.0 Beta 1 by injecting malicious SQL queries via the 'id' parameter in multiple admin endpoints. The PoC uses UNION-based SQLi to extract database version information.
Description
Multiple SQL injection vulnerabilities in TopicsViewer 3.0 Beta 1 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) edit_block.php, (2) edit_cat.php, (3) edit_note.php, or (4) rmv_topic.php in admincp/.
Exploits (1)
The exploit demonstrates SQL injection vulnerabilities in TopicsViewer v3.0 Beta 1 by injecting malicious SQL queries via the 'id' parameter in multiple admin endpoints. The PoC uses UNION-based SQLi to extract database version information.