Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-25541. PoCs published by Ahmet Ümit BAYRAM.
AI-analyzed exploit summary The exploit demonstrates time-based blind SQL injection vulnerabilities in Netartmedia PHP Mall 4.1. It provides two PoC requests targeting the 'id' parameter in 'index.php' and the 'Email' parameter in 'loginaction.php', both using SLEEP functions to confirm the vulnerability.
Description
Netartmedia PHP Mall 4.1 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through unvalidated parameters. Attackers can inject time-based blind SQL payloads via the 'id' parameter in index.php or the 'Email' parameter in loginaction.php to extract sensitive database information.
Exploits (1)
The exploit demonstrates time-based blind SQL injection vulnerabilities in Netartmedia PHP Mall 4.1. It provides two PoC requests targeting the 'id' parameter in 'index.php' and the 'Email' parameter in 'loginaction.php', both using SLEEP functions to confirm the vulnerability.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N