CVE-2019-25640
HIGHInout Article Base CMS Lastest SQL Injection via portalLogin.php
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25640. PoCs published by Ahmet Ümit BAYRAM.
AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in Inout Article Base CMS via the 'p' and 'u' GET parameters in portalLogin.php. The attack patterns use time-based blind SQLi techniques with XOR and sleep functions to confirm vulnerability.
Description
Inout Article Base CMS contains SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries through the 'p' and 'u' parameters. Attackers can inject SQL code using XOR-based payloads in GET requests to portalLogin.php to extract sensitive database information or cause denial of service through time-based attacks.
Exploits (1)
The exploit demonstrates SQL injection vulnerabilities in Inout Article Base CMS via the 'p' and 'u' GET parameters in portalLogin.php. The attack patterns use time-based blind SQLi techniques with XOR and sleep functions to confirm vulnerability.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N