CVE-2018-17110
CRITICALSimple POS 4.0.24 - SQL Injection via Management Panel Search Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-17110. PoCs published by Renos Nikolaou.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Simple POS 4.0.24 via the 'columns[0][search][value]' parameter. The PoC includes a time-based blind SQLi payload that triggers a 15-second delay, confirming the vulnerability.
Description
Simple POS 4.0.24 allows SQL Injection via a products/get_products/ columns[0][search][value] parameter in the management panel, as demonstrated by products/get_products/1.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Simple POS 4.0.24 via the 'columns[0][search][value]' parameter. The PoC includes a time-based blind SQLi payload that triggers a 15-second delay, confirming the vulnerability.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H