CVE-2015-6944

JSP/MySQL Administrador Web 1 - Cross-Site Request Forgery via cmd Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-6944.

AI-analyzed exploit summary The exploit demonstrates CSRF and XSS vulnerabilities in JSPMySQL Administrador v.1. It includes functional PoC code for CSRF to drop a MySQL database and an XSS payload delivered via a crafted URL.

Description

Cross-site request forgery (CSRF) vulnerability in JSP/MySQL Administrador Web 1 allows remote attackers to hijack the authentication of users for requests that execute arbitrary SQL commands via the cmd parameter to sys/sys/listaBD2.jsp.

Exploits (1)

exploitdb WORKING POC
webappsjsp
https://www.exploit-db.com/exploits/38098

The exploit demonstrates CSRF and XSS vulnerabilities in JSPMySQL Administrador v.1. It includes functional PoC code for CSRF to drop a MySQL database and an XSS payload delivered via a crafted URL.

Classification
Working Poc 95%
Attack Type
Xss | Sqli
Complexity
Trivial
Reliability
Reliable
Target: JSPMySQL Administrador v.1
No auth needed
Prerequisites: Victim must visit a malicious webpage or click a crafted link
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Scores

EPSS 0.0243
EPSS Percentile 82.1%

Details

CWE
CWE-352
Status published
Products (1)
jsp\/mysql_administrador_web_project/jsp\/mysql_administrador_web 1.0
Published Sep 15, 2015
Tracked Since Feb 18, 2026