CVE-2018-25371
HIGHmooSocial Store Plugin 2.6 SQL Injection via product parameter
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2018-25371. PoCs published by Andrea Bocchetti.
AI-analyzed exploit summary This exploit demonstrates a blind SQL injection vulnerability in the mooSocial Store Plugin 2.6, where the 'product' parameter in the URL is vulnerable to boolean-based and time-based SQL injection attacks. The provided payloads show how an attacker can inject malicious SQL queries to extract data or delay responses.
Description
mooSocial Store Plugin 2.6 contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries through the product parameter in URL rewrite functionality. Attackers can inject SQL code using boolean-based blind, time-based blind, or stacked query techniques in the product URI parameter to extract sensitive database information.
Exploits (1)
This exploit demonstrates a blind SQL injection vulnerability in the mooSocial Store Plugin 2.6, where the 'product' parameter in the URL is vulnerable to boolean-based and time-based SQL injection attacks. The provided payloads show how an attacker can inject malicious SQL queries to extract data or delay responses.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N