CVE-2017-17599
CRITICALAdvance Online Learning Management Script 3.1 - SQL Injection via courselist.php subcatid or popcourseid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-17599. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Advance Online Learning Management Script 3.1 via the 'subcatid' and 'popcourseid' GET parameters. It includes payloads for UNION-based, boolean-based blind, and time-based blind SQL injection attacks.
Description
Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in Advance Online Learning Management Script 3.1 via the 'subcatid' and 'popcourseid' GET parameters. It includes payloads for UNION-based, boolean-based blind, and time-based blind SQL injection attacks.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H