CVE-2018-5973
CRITICALProfessional Local Directory Script 1.0 - SQL Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-5973. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Professional Local Directory Script 1.0 via the 'IndustryID' parameter in two endpoints. The PoC includes crafted SQL payloads to extract database information.
Description
SQL Injection exists in Professional Local Directory Script 1.0 via the sellers_subcategories.php IndustryID parameter, or the suppliers.php IndustryID or CategoryID parameter.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in Professional Local Directory Script 1.0 via the 'IndustryID' parameter in two endpoints. The PoC includes crafted SQL payloads to extract database information.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H