CVE-2014-1637
Command School Student Management System <1.06.01 - Info Disclosure
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-1637. PoCs published by AtT4CKxT3rR0r1ST.
AI-analyzed exploit summary The provided code is a writeup describing multiple vulnerabilities in Command School Student Management System, including SQL injection, CSRF, XSS, HTML injection, and security bypass. It includes a snippet of vulnerable PHP code from a backup script but lacks a functional exploit.
Description
Command School Student Management System 1.06.01 does not properly restrict access to sw/backup/backup_ray2.php, which allows remote attackers to download a database backup via a direct request.
Exploits (1)
The provided code is a writeup describing multiple vulnerabilities in Command School Student Management System, including SQL injection, CSRF, XSS, HTML injection, and security bypass. It includes a snippet of vulnerable PHP code from a backup script but lacks a functional exploit.