CVE-2019-25732
HIGHPHP EI-Tube Script 3 SQL Injection via search parameter
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25732. PoCs published by Meisam Monsef.
AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in PHP EI-Tube Script version 3. It leverages a crafted search query to inject SQL commands, allowing unauthorized data extraction such as user information and database version.
Description
PHP EI-Tube Script 3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can send GET requests to the search endpoint with crafted SQL payloads in the query parameter to extract sensitive database information including usernames, passwords, and version details.
Exploits (1)
The exploit demonstrates a SQL injection vulnerability in PHP EI-Tube Script version 3. It leverages a crafted search query to inject SQL commands, allowing unauthorized data extraction such as user information and database version.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N