CVE-2015-1400

NPDS Revolution 13 - SQL Injection via Search Query Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-1400. PoCs published by Narendra Bhati.

AI-analyzed exploit summary This is a detailed writeup describing a time-based SQL injection vulnerability in NPDS CMS Revolution-13 via the `query` parameter in `search.php`. The PoC demonstrates exploitation via a POST request with a malicious payload.

Description

SQL injection vulnerability in search.php in NPDS Revolution 13 allows remote attackers to execute arbitrary SQL commands via the query parameter.

Exploits (1)

exploitdb WRITEUP
by Narendra Bhati · textwebappsphp
https://www.exploit-db.com/exploits/35950

This is a detailed writeup describing a time-based SQL injection vulnerability in NPDS CMS Revolution-13 via the `query` parameter in `search.php`. The PoC demonstrates exploitation via a POST request with a malicious payload.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: NPDS CMS Revolution-13
No auth needed
Prerequisites: Access to the target application's search.php endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4

Scores

EPSS 0.0241
EPSS Percentile 82.0%

Details

CWE
CWE-89
Status published
Products (1)
npds/revolution 13.0
Published Feb 03, 2015
Tracked Since Feb 18, 2026