Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-37033. PoCs published by ratboy.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Infor Storefront B2B/B2C via the 'usr_name' and 'itm_id' parameters. It includes SQLmap commands for automated exploitation and manual SQL injection examples.
Description
Infor Storefront B2B 1.0 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'usr_name' parameter in login requests. Attackers can exploit the vulnerability by injecting malicious SQL code into the 'usr_name' parameter to potentially extract or modify database information.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in Infor Storefront B2B/B2C via the 'usr_name' and 'itm_id' parameters. It includes SQLmap commands for automated exploitation and manual SQL injection examples.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N