Exploitation Summary
EIP tracks 1 public exploit for CVE-2014-2023. PoCs published by tintinweb.
AI-analyzed exploit summary This Python script exploits a time-based blind SQL injection vulnerability in Tapatalk plugin versions <= 5.2.1 via the `unsubscribe_topic` or `unsubscribe_forum` XML-RPC methods. It includes functionality for detecting vulnerable installations and brute-forcing data extraction.
Description
Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allow remote attackers to execute arbitrary SQL commands via a crafted xmlrpc API request to (1) unsubscribe_forum.php or (2) unsubscribe_topic.php in mobiquo/functions/.
Exploits (1)
This Python script exploits a time-based blind SQL injection vulnerability in Tapatalk plugin versions <= 5.2.1 via the `unsubscribe_topic` or `unsubscribe_forum` XML-RPC methods. It includes functionality for detecting vulnerable installations and brute-forcing data extraction.
References (5)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H