packetstormsecurity.com
http://packetstormsecurity.com/files/159262/Visitor-Management-System-In-PHP-1.0-SQL-Injection.html CVE-2020-25760
HIGH
Visitor Management System in PHP 1.0 - SQL Injection (Authenticated)
Record summary
CVE-2020-25760 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
Projectworlds Visitor Management System in PHP 1.0 allows SQL Injection. The file front.php does not perform input validation on the 'rid' parameter. An attacker can append SQL queries to the input to extract sensitive information from the database.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBVisitor Management System in PHP 1.0 - SQL Injection (Authenticated)ExploitDB exploitby Rahul RamkumarNot analyzed1 file
References
6packetstormsecurity.com
http://packetstormsecurity.com/files/159637/Visitor-Management-System-In-PHP-1.0-SQL-Injection.html 20200922 Visitor Management System in PHP 1.0 - Authenticated SQL Injectionmailing list
http://seclists.org/fulldisclosure/2020/Sep/43 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-25760 packetstormsecurity.com
https://packetstormsecurity.com/files/author/15149 exploit-db.com
https://www.exploit-db.com/exploits/48911