Exploitation Summary
EIP tracks 1 public exploit for CVE-2014-9145.
AI-analyzed exploit summary The provided exploit demonstrates multiple SQL injection vulnerabilities in FiyoCMS 2.0.1.8, including UNION-based, error-based, and time-based blind SQLi. It includes specific payloads and SQLmap outputs for parameters like 'id', 'cat', 'user', and 'level'.
Description
Multiple SQL injection vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an edit action to dapur/index.php; (2) cat, (3) user, or (4) level parameter to dapur/apps/app_article/controller/article_list.php; or (5) email parameter in an email action or (6) username parameter in a user action to dapur/apps/app_user/controller/check_user.php.
Exploits (1)
The provided exploit demonstrates multiple SQL injection vulnerabilities in FiyoCMS 2.0.1.8, including UNION-based, error-based, and time-based blind SQLi. It includes specific payloads and SQLmap outputs for parameters like 'id', 'cat', 'user', and 'level'.