CVE-2015-3934
CRITICALFiyo CMS 2.0_1.9.1 - SQL Injection via id Parameter or user Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2015-3934. PoCs published by cfreer.
AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 via the 'id' parameter in rating.php and the 'user' parameter in login functionality. The PoC includes payloads to trigger time-based SQLi using sleep functions.
Description
Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/app_article/controller/rating.php or (2) user parameter to user/login.
Exploits (1)
The exploit demonstrates SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 via the 'id' parameter in rating.php and the 'user' parameter in login functionality. The PoC includes payloads to trigger time-based SQLi using sleep functions.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H