CVE-2018-7474
CRITICALTextpattern < 4.6.2 - SQL Injection via qty Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-7474. PoCs published by Manuel García Cárdenas.
AI-analyzed exploit summary The document describes a SQL injection vulnerability in Textpattern CMS <= 4.6.2, where the 'qty' parameter in 'index.php' is exploitable via HTTP/1.0. The PoC demonstrates SQLi via the 'into outfile' technique, but no executable code is provided.
Description
An issue was discovered in Textpattern CMS 4.6.2 and earlier. It is possible to inject SQL code in the variable "qty" on the page index.php.
Exploits (1)
The document describes a SQL injection vulnerability in Textpattern CMS <= 4.6.2, where the 'qty' parameter in 'index.php' is exploitable via HTTP/1.0. The PoC demonstrates SQLi via the 'into outfile' technique, but no executable code is provided.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H