CVE-2014-3246
Collabtive 1.2 - Authenticated SQL Injection via Folder Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-3246. PoCs published by Deepak Rathore.
AI-analyzed exploit summary This is a writeup detailing a SQL injection vulnerability in Collabtive 1.12, where the 'folder' parameter in 'manageajax.php' is vulnerable to SQLi. The proof of vulnerability is demonstrated via an error-based SQL injection payload.
Description
SQL injection vulnerability in Collabtive 1.2 allows remote authenticated users to execute arbitrary SQL commands via the folder parameter in a fileview_list action to manageajax.php.
Exploits (1)
This is a writeup detailing a SQL injection vulnerability in Collabtive 1.12, where the 'folder' parameter in 'manageajax.php' is vulnerable to SQLi. The proof of vulnerability is demonstrated via an error-based SQL injection payload.