Exploitation Summary
EIP tracks 1 public exploit for CVE-2019-25672. PoCs published by Mehmet EMIROGLU.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in PilusCart 1.4.1 via the 'send' parameter in a POST request. The attack pattern uses a boolean-based string technique with RLIKE and case statements to inject malicious SQL.
Description
PilusCart 1.4.1 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'send' parameter. Attackers can submit POST requests to the comment submission endpoint with RLIKE-based boolean SQL injection payloads to extract sensitive database information.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in PilusCart 1.4.1 via the 'send' parameter in a POST request. The attack pattern uses a boolean-based string technique with RLIKE and case statements to inject malicious SQL.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N