Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-25481. PoCs published by Ahmet Ümit BAYRAM.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in iScripts ReserveLogic via the 'jqSearchDestination' POST parameter. The payload uses a CASE statement to trigger a boolean-based blind SQLi, confirming the vulnerability.
Description
iScripts ReserveLogic contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the jqSearchDestination parameter. Attackers can send POST requests to the search endpoint with crafted SQL payloads to extract sensitive database information.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in iScripts ReserveLogic via the 'jqSearchDestination' POST parameter. The payload uses a CASE statement to trigger a boolean-based blind SQLi, confirming the vulnerability.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N