Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-1000890. PoCs published by Sainadh Jamalpur.
AI-analyzed exploit summary This exploit demonstrates a time-based blind SQL injection vulnerability in FrontAccounting 2.4.5 via the 'filterType' parameter in the attachments.php file. The PoC uses a sleep function to confirm the vulnerability.
Description
FrontAccounting 2.4.5 contains a Time Based Blind SQL Injection vulnerability in the parameter "filterType" in /attachments.php that can allow the attacker to grab the entire database of the application.
Exploits (1)
This exploit demonstrates a time-based blind SQL injection vulnerability in FrontAccounting 2.4.5 via the 'filterType' parameter in the attachments.php file. The PoC uses a sleep function to confirm the vulnerability.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N