Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-25189. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Data Center Audit 2.6.2 via the 'username' parameter in the login form. The payload extracts database information, including user, database name, and version, through a crafted SQL query.
Description
Data Center Audit 2.6.2 contains an SQL injection vulnerability in the username parameter of dca_login.php that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit crafted SQL payloads through POST requests to extract sensitive database information including usernames, database names, and version details.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Data Center Audit 2.6.2 via the 'username' parameter in the login form. The payload extracts database information, including user, database name, and version, through a crafted SQL query.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N