Exploitation Summary
EIP tracks 1 public exploit for CVE-2015-1471. PoCs published by Steffen Rösemann.
AI-analyzed exploit summary The advisory describes a SQL injection vulnerability in Pragyan CMS v.3, allowing unauthenticated attackers to exploit the user-profile endpoint. The example provided demonstrates a UNION-based SQLi to extract database information and version details.
Description
SQL injection vulnerability in userprofile.lib.php in Pragyan CMS 3.0 allows remote attackers to execute arbitrary SQL commands via the user parameter to the default URI.
Exploits (1)
The advisory describes a SQL injection vulnerability in Pragyan CMS v.3, allowing unauthenticated attackers to exploit the user-profile endpoint. The example provided demonstrates a UNION-based SQLi to extract database information and version details.