CVE-2019-25303
HIGHTheJshen ContentManagementSystem 1.04 - SQL Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25303. PoCs published by cakes.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in TheJshen contentManagementSystem 1.04 via the 'id' GET parameter. It includes payloads for boolean-based blind, time-based blind, and UNION-based SQL injection techniques.
Description
TheJshen ContentManagementSystem 1.04 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'id' GET parameter. Attackers can exploit boolean-based, time-based, and UNION-based SQL injection techniques to extract or manipulate database information by crafting malicious query payloads.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in TheJshen contentManagementSystem 1.04 via the 'id' GET parameter. It includes payloads for boolean-based blind, time-based blind, and UNION-based SQL injection techniques.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N