CVE-2017-15987
CRITICALfake_magazine_cover_script - SQL Injection via rate.php value parameter or content.php id parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-15987. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in the Fake Magazine Cover Script, allowing an attacker to inject SQL commands via the 'value' and 'id' parameters in 'rate.php' and 'content.php' respectively. The PoC includes payloads for boolean-based blind and time-based blind SQL injection.
Description
Fake Magazine Cover Script allows SQL Injection via the rate.php value parameter or the content.php id parameter.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in the Fake Magazine Cover Script, allowing an attacker to inject SQL commands via the 'value' and 'id' parameters in 'rate.php' and 'content.php' respectively. The PoC includes payloads for boolean-based blind and time-based blind SQL injection.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H