Exploitation Summary
EIP tracks 2 public exploits for CVE-2014-1618. PoCs published by AtT4CKxT3rR0r1ST.
AI-analyzed exploit summary The provided text describes a SQL injection vulnerability in UAEPD Shopping Cart Script, where the 'cat_id' parameter in 'products.php' is not properly sanitized. No actual exploit code is included, only a description and an example URL.
Description
Multiple SQL injection vulnerabilities in UAEPD Shopping Cart Script allow remote attackers to execute arbitrary SQL commands via the (1) cat_id or (2) p_id parameter to products.php or id parameter to (3) page.php or (4) news.php.
Exploits (2)
The provided text describes a SQL injection vulnerability in UAEPD Shopping Cart Script, where the 'cat_id' parameter in 'products.php' is not properly sanitized. No actual exploit code is included, only a description and an example URL.
The provided text describes a SQL injection vulnerability in UAEPD Shopping Cart Script, where the 'id' parameter in 'news.php' is not properly sanitized. It lacks actual exploit code, serving only as a vulnerability description.