Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-20246. PoCs published by TAD GROUP.
AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in the KittyCatfish WordPress plugin (version 2.2) via the unescaped 'kc_ad' parameter. It provides sqlmap commands to exploit the vulnerability, confirming it as a boolean-based blind and time-based blind SQLi.
Description
KittyCatfish 2.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to read database contents by exploiting an unescaped GET parameter. Attackers can inject SQL code through the 'kc_ad' parameter in base.css.php or kittycatfish.php to extract sensitive database information using boolean-based blind or time-based blind techniques.
Exploits (1)
The exploit demonstrates a SQL injection vulnerability in the KittyCatfish WordPress plugin (version 2.2) via the unescaped 'kc_ad' parameter. It provides sqlmap commands to exploit the vulnerability, confirming it as a boolean-based blind and time-based blind SQLi.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N