Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-25462. PoCs published by Ahmet Ümit BAYRAM.
AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in Web Ofisi Rent a Car v3 via multiple GET parameters (kategori[], klima[], vites[], yakit[]). It includes functional payloads that can be used to test for time-based and boolean-based SQLi.
Description
Web Ofisi Rent a Car v3 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'klima' parameter. Attackers can send GET requests to with malicious 'klima' values to extract sensitive database information or cause denial of service.
Exploits (1)
The exploit demonstrates SQL injection vulnerabilities in Web Ofisi Rent a Car v3 via multiple GET parameters (kategori[], klima[], vites[], yakit[]). It includes functional payloads that can be used to test for time-based and boolean-based SQLi.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N