CVE-2017-16561
CRITICALIngenious School Management System 2.3.0 - SQL Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-16561. PoCs published by Giulio Comi.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Ingenious School Management System 2.3.0 via the 'friend_index' GET parameter. It includes payloads for boolean-based blind and time-based blind SQL injection attacks.
Description
/view/friend_profile.php in Ingenious School Management System 2.3.0 is vulnerable to Boolean-based and Time-based SQL injection in the 'friend_index' parameter of a GET request.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Ingenious School Management System 2.3.0 via the 'friend_index' GET parameter. It includes payloads for boolean-based blind and time-based blind SQL injection attacks.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H