CVE-2017-15985
CRITICALBasic B2B Script - SQL Injection via product_view1.php pid or id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-15985. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Basic B2B Script, allowing an attacker to inject malicious SQL commands via the 'pid' and 'id' parameters in specific PHP files. The PoC includes payloads for time-based blind and boolean-based blind SQL injection.
Description
Basic B2B Script allows SQL Injection via the product_view1.php pid or id parameter.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in Basic B2B Script, allowing an attacker to inject malicious SQL commands via the 'pid' and 'id' parameters in specific PHP files. The PoC includes payloads for time-based blind and boolean-based blind SQL injection.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H