Exploitation Summary
EIP tracks 1 public exploit for CVE-2014-2317. PoCs published by High-Tech Bridge SA.
AI-analyzed exploit summary The advisory details two vulnerabilities in OpenDocMan: a SQL Injection via the 'add_value' parameter in 'ajax_udf.php' and an Improper Access Control issue in 'signup.php' allowing privilege escalation. Both vulnerabilities are described with exploitation examples.
Description
SQL injection vulnerability in ajax_udf.php in OpenDocMan before 1.2.7.2 allows remote attackers to execute arbitrary SQL commands via the table parameter. NOTE: some of these details are obtained from third party information.
Exploits (1)
The advisory details two vulnerabilities in OpenDocMan: a SQL Injection via the 'add_value' parameter in 'ajax_udf.php' and an Improper Access Control issue in 'signup.php' allowing privilege escalation. Both vulnerabilities are described with exploitation examples.