CVE-2017-17612
CRITICALHot Scripts Clone 3.1 - SQL Injection via Categories Subctid or Mctid Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2017-17612. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Hot Scripts Clone 3.1 via the 'subctid' and 'mctid' parameters. The PoC includes payloads to extract database information and table names.
Description
Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.
Exploits (2)
This exploit demonstrates SQL injection vulnerabilities in Hot Scripts Clone 3.1 via the 'subctid' and 'mctid' parameters. The PoC includes payloads to extract database information and table names.
This exploit demonstrates a SQL injection vulnerability in Hot Scripts Clone Script 1.0 via the 'mctid' and 'subctid' parameters. The PoC includes a crafted SQL query that extracts table and column names from the information_schema database.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H