CVE-2017-12759

CRITICAL

SOA School Management 3.0 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-12759. PoCs published by Ihsan Sencan.

AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in SOA School Management 3.0 via multiple endpoints, allowing attackers to extract sensitive data such as usernames and passwords. The PoC includes crafted SQL payloads for various parameters.

Description

Ynet Interactive - http://demo.ynetinteractive.com/soa/ SOA School Management 3.0 is affected by: SQL Injection. The impact is: Code execution (remote).

Exploits (1)

exploitdb WORKING POC
by Ihsan Sencan · textwebappsphp
https://www.exploit-db.com/exploits/42499

The exploit demonstrates SQL injection vulnerabilities in SOA School Management 3.0 via multiple endpoints, allowing attackers to extract sensitive data such as usernames and passwords. The PoC includes crafted SQL payloads for various parameters.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: SOA School Management 3.0
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Product x_refsource_misc
http://demo.ynetinteractive.com/soa/
Not Applicable x_refsource_misc
http://soa.com
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/42499

Scores

CVSS v3 9.8
EPSS 0.0361
EPSS Percentile 88.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-89
Status published
Products (1)
ynetinteractive/soa_school_management 3.0
Published May 09, 2019
Tracked Since Feb 18, 2026