CVE-2018-12052
CRITICALPHP Scripts Mall Schools Alert Mgt - SQL Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-12052. PoCs published by M3@Pandas.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in the 'get_sec.php' endpoint of the Schools Alert Management Script. The PoC uses a UNION-based SQLi with inline comments to bypass filters and extract database information including user, database name, and version.
Description
SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in the 'get_sec.php' endpoint of the Schools Alert Management Script. The PoC uses a UNION-based SQLi with inline comments to bypass filters and extract database information including user, database name, and version.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H