Exploitation Summary
EIP tracks 1 public exploit for CVE-2015-3933. PoCs published by cfreer.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in GenixCMS 0.0.3 via the 'email' and 'userid' parameters in register.php. The PoC includes HTTP requests with crafted payloads to trigger SQL errors and extract database information.
Description
Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote attackers to execute arbitrary SQL commands via the (1) email parameter or (2) userid parameter to register.php.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in GenixCMS 0.0.3 via the 'email' and 'userid' parameters in register.php. The PoC includes HTTP requests with crafted payloads to trigger SQL errors and extract database information.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H