CVE-2019-16692
CRITICALphpipam < 1.4 - SQL Injection via Custom Fields Filter Table Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2019-16692. PoCs published by Kevin Kirsche, kkirsche.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in phpIPAM 1.4 by leveraging the `updatexml` function to extract database information. It authenticates as an admin and injects payloads into the `table` parameter of the custom field filter.
Description
phpIPAM 1.4 allows SQL injection via the app/admin/custom-fields/filter-result.php table parameter when action=add is used.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in phpIPAM 1.4 by leveraging the `updatexml` function to extract database information. It authenticates as an admin and injects payloads into the `table` parameter of the custom field filter.
This repository contains a functional Python exploit for CVE-2019-16692, a SQL injection vulnerability in phpIPAM 1.4. The exploit leverages the `updatexml` function to extract database information via error-based SQLi.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H