CVE-2017-17633
CRITICALMultiplex Movie Theater Booking Script 3.1.5 - SQL Injection via moid or eid Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-17633. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in Multiplex Movie Theater Booking Script 3.1.5 via three distinct endpoints. It uses UNION-based SQLi to extract database information, including table names, column names, and admin credentials.
Description
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php moid parameter, or event-detail.php eid parameter.
Exploits (1)
The exploit demonstrates SQL injection vulnerabilities in Multiplex Movie Theater Booking Script 3.1.5 via three distinct endpoints. It uses UNION-based SQLi to extract database information, including table names, column names, and admin credentials.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H