CVE-2019-25578
HIGHphpTransformer 2016.9 SQL Injection via GeneratePDF.php
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25578. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in phpTransformer 2016.9 via the 'idnews' parameter in GeneratePDF.php. The payload injects a sleep command to confirm the vulnerability.
Description
phpTransformer 2016.9 contains an SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the idnews parameter. Attackers can send crafted GET requests to GeneratePDF.php with SQL payloads in the idnews parameter to extract sensitive database information or manipulate queries.
Exploits (1)
The exploit demonstrates a SQL injection vulnerability in phpTransformer 2016.9 via the 'idnews' parameter in GeneratePDF.php. The payload injects a sleep command to confirm the vulnerability.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N