CVE-2018-18619
CRITICALAdvanced Comment System 1.0 - SQL Injection via Page Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-18619. PoCs published by Rafael Pedrero.
AI-analyzed exploit summary The exploit demonstrates an SQL injection vulnerability in Advanced Comment System v1.0 via the 'page' parameter in admin.php. The PoC uses a UNION-based SQLi to extract data, confirming the vulnerability.
Description
internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query, allowing remote attackers to execute the sqli attack via a URL in the "page" parameter. NOTE: The product is discontinued.
Exploits (1)
The exploit demonstrates an SQL injection vulnerability in Advanced Comment System v1.0 via the 'page' parameter in admin.php. The PoC uses a UNION-based SQLi to extract data, confirming the vulnerability.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H