CVE-2017-17580
CRITICALFS Linkedin Clone 1.0 - SQL Injection via group.php grid parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-17580. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in FS Linkedin Clone 1.0 via three different endpoints (`group.php`, `profile.php`, and `company_details.php`). The PoC includes crafted SQL queries to extract table names and column information from the database.
Description
FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.php id parameter.
Exploits (1)
The exploit demonstrates SQL injection vulnerabilities in FS Linkedin Clone 1.0 via three different endpoints (`group.php`, `profile.php`, and `company_details.php`). The PoC includes crafted SQL queries to extract table names and column information from the database.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H