CVE-2017-15579
CRITICALphp_melody < 2.7.3 - SQL Injection via aa_pages_per_page Cookie
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-15579. PoCs published by SecuriTeam.
AI-analyzed exploit summary The document describes three vulnerabilities in PHP Melody 2.7.3: a stored XSS leading to admin account takeover, and two SQL injection flaws (one in POST parameter and another in a cookie value). It includes payload examples but lacks executable exploit code.
Description
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php.
Exploits (1)
The document describes three vulnerabilities in PHP Melody 2.7.3: a stored XSS leading to admin account takeover, and two SQL injection flaws (one in POST parameter and another in a cookie value). It includes payload examples but lacks executable exploit code.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H