Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-17428. PoCs published by Dino Barlattani.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in OPAC EasyWeb Five 5.7 via the 'biblio' parameter. The PoC includes a crafted SQL payload designed to trigger a boolean-based blind SQL injection, which can be used with tools like sqlmap to dump the database.
Description
An issue was discovered in OPAC EasyWeb Five 5.7. There is SQL injection via the w2001/index.php?scelta=campi biblio parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in OPAC EasyWeb Five 5.7 via the 'biblio' parameter. The PoC includes a crafted SQL payload designed to trigger a boolean-based blind SQL injection, which can be used with tools like sqlmap to dump the database.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H