CVE-2019-25576
HIGHKepler Wallpaper Script 1.1 SQL Injection via category
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25576. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in Kepler Wallpaper Script 1.1 via the 'category' parameter. The URL-encoded payload injects a UNION SELECT statement to extract database information, confirming the vulnerability.
Description
Kepler Wallpaper Script 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the category parameter. Attackers can send GET requests to the category endpoint with URL-encoded SQL UNION statements to extract database information including usernames, database names, and MySQL version details.
Exploits (1)
The exploit demonstrates a SQL injection vulnerability in Kepler Wallpaper Script 1.1 via the 'category' parameter. The URL-encoded payload injects a UNION SELECT statement to extract database information, confirming the vulnerability.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N