CVE-2014-3414
Sharetronix < 3.3 - Cross-Site Request Forgery via Admin Privilege Assignment
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-3414.
AI-analyzed exploit summary The exploit demonstrates SQL injection (CVE-2014-3415) and CSRF (CVE-2014-3414) vulnerabilities in Sharetronix 3.3. The SQLi exploit writes a PHP file to the MySQL server, while the CSRF exploit grants admin privileges to an arbitrary user.
Description
Cross-site request forgery (CSRF) vulnerability in Sharetronix before 3.4 allows remote attackers to hijack the authentication of administrators for requests that add administrative privileges to a user via the admin parameter to admin/administrators.
Exploits (1)
The exploit demonstrates SQL injection (CVE-2014-3415) and CSRF (CVE-2014-3414) vulnerabilities in Sharetronix 3.3. The SQLi exploit writes a PHP file to the MySQL server, while the CSRF exploit grants admin privileges to an arbitrary user.