CVE-2019-25509
HIGHXooDigital Latest - Unauthenticated SQL Injection via 'p' Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25509. PoCs published by Ahmet Ümit BAYRAM.
AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in XooDigital's 'results.php' via the 'p' GET parameter. The payload bypasses authentication by injecting a tautology (OR NOT 7970=7970) to manipulate the SQL query.
Description
XooDigital Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'p' parameter. Attackers can send GET requests to results.php with malicious 'p' values to extract sensitive database information.
Exploits (1)
The exploit demonstrates a SQL injection vulnerability in XooDigital's 'results.php' via the 'p' GET parameter. The payload bypasses authentication by injecting a tautology (OR NOT 7970=7970) to manipulate the SQL query.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N