CVE-2018-18800
CRITICALTubigan Welcome to our Resort 1.0 - SQL Injection via index.php or admin/login.php Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-18800. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in the PayPal/Credit Card/Debit Card Payment 1.0 application. It includes two distinct SQLi payloads targeting the 'accomodation' and 'rooms' endpoints, both leveraging UNION-based techniques to extract database schema information.
Description
The Tubigan "Welcome to our Resort" 1.0 software allows SQL Injection via index.php?p=accomodation&q=[SQL], index.php?p=rooms&q=[SQL], or admin/login.php.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in the PayPal/Credit Card/Debit Card Payment 1.0 application. It includes two distinct SQLi payloads targeting the 'accomodation' and 'rooms' endpoints, both leveraging UNION-based techniques to extract database schema information.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H