CVE-2017-17651
CRITICALPaid To Read Script 2.0.5 - SQL Injection via Admin Panel Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-17651. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in Paid To Read Script 2.0.5 via three distinct endpoints, using UNION-based techniques to extract database information such as table names, column names, user, database, and version details.
Description
Paid To Read Script 2.0.5 has SQL Injection via the admin/userview.php uid parameter, the admin/viewemcamp.php fnum parameter, or the admin/viewvisitcamp.php fn parameter.
Exploits (1)
The exploit demonstrates SQL injection vulnerabilities in Paid To Read Script 2.0.5 via three distinct endpoints, using UNION-based techniques to extract database information such as table names, column names, user, database, and version details.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H