CVE-2014-3871
Geodesic Solutions GeoCore MAX 7.3.3 - SQL Injection via Register.php Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-3871. PoCs published by Esac.
AI-analyzed exploit summary This exploit demonstrates a time-based blind SQL injection vulnerability in GeoCore MAX DB Ver. 7.3.3. It provides examples of injecting sleep commands into GET and POST parameters to confirm the vulnerability.
Description
Multiple SQL injection vulnerabilities in register.php in Geodesic Solutions GeoCore MAX 7.3.3 (formerly GeoClassifieds and GeoAuctions) allow remote attackers to execute arbitrary SQL commands via the (1) c[password] or (2) c[username] parameter. NOTE: the b parameter to index.php vector is already covered by CVE-2006-3823.
Exploits (1)
This exploit demonstrates a time-based blind SQL injection vulnerability in GeoCore MAX DB Ver. 7.3.3. It provides examples of injecting sleep commands into GET and POST parameters to confirm the vulnerability.