CVE-2017-17648
CRITICALEntrepreneur Dating Script 2.0.1 - SQL Injection via search_result.php Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-17648. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Entrepreneur Dating Script 2.0.1 via multiple parameters (marital, gender, country, profileid). The payload uses UNION-based injection to extract data from information_schema.columns.
Description
Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid parameter.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in Entrepreneur Dating Script 2.0.1 via multiple parameters (marital, gender, country, profileid). The payload uses UNION-based injection to extract data from information_schema.columns.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H