CVE-2018-12912
HIGHHongCMS 3.0.0 - SQL Injection via Database Empty Table URI Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-12912. PoCs published by Hzllaga.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in HongCMS 3.0.0 via the 'tablename' parameter in the admin database operation endpoint. The payload uses MySQL's UPDATEXML function to extract database version information.
Description
An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via an admin/index.php/database/operate?dbaction=emptytable&tablename= URI.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in HongCMS 3.0.0 via the 'tablename' parameter in the admin database operation endpoint. The payload uses MySQL's UPDATEXML function to extract database version information.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H