CVE-2014-8596
php-fusion 7.02.07 - Authenticated SQL Injection via submit_id or status Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-8596. PoCs published by XLabs Security.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in PHP-Fusion 7.02.07 via two HTTP GET requests targeting the 'submissions.php' and 'members.php' endpoints. The PoC shows how an attacker can inject malicious SQL queries through the 'submit_id' and 'status' parameters.
Description
Multiple SQL injection vulnerabilities in PHP-Fusion 7.02.07 allow remote authenticated users to execute arbitrary SQL commands via the (1) submit_id parameter in a 2 action to files/administration/submissions.php or (2) status parameter to files/administration/members.php.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in PHP-Fusion 7.02.07 via two HTTP GET requests targeting the 'submissions.php' and 'members.php' endpoints. The PoC shows how an attacker can inject malicious SQL queries through the 'submit_id' and 'status' parameters.