Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-19245. PoCs published by hyp3rlinx.
AI-analyzed exploit summary This exploit demonstrates a pre-authentication SQL injection vulnerability in Xinet Elegant 6 Asset Lib Web UI 6.1.655. It allows dumping database tables, usernames, and passwords by manipulating the 'LoginForm[username]' parameter.
Description
NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[username] field when double quotes are used.
Exploits (1)
This exploit demonstrates a pre-authentication SQL injection vulnerability in Xinet Elegant 6 Asset Lib Web UI 6.1.655. It allows dumping database tables, usernames, and passwords by manipulating the 'LoginForm[username]' parameter.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H