CVE-2020-35597
HIGHVictor CMS 1.0 - SQL Injection via c_id, p_id, u_id, and edit Parameters
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-35597. PoCs published by Furkan Göksel.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Victor CMS 1.0 via multiple parameters (c_id, p_id, u_id, edit) in authenticated admin pages. The PoC includes a time-based blind SQLi example using SLEEP(10).
Description
Victor CMS 1.0 is vulnerable to SQL injection via c_id parameter of admin_edit_comment.php, p_id parameter of admin_edit_post.php, u_id parameter of admin_edit_user.php, and edit parameter of admin_update_categories.php.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in Victor CMS 1.0 via multiple parameters (c_id, p_id, u_id, edit) in authenticated admin pages. The PoC includes a time-based blind SQLi example using SLEEP(10).
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H