Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-37035. PoCs published by KeopssGroup0day_Inc.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in e-learning Php Script 0.1.0 via the 'search' parameter. The payload uses a time-based blind SQLi technique to extract data from the database.
Description
e-Learning PHP Script 0.1.0 contains a SQL injection vulnerability in the search functionality that allows attackers to manipulate database queries through unvalidated user input. Attackers can inject malicious SQL code in the 'search' parameter to potentially extract, modify, or access sensitive database information.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in e-learning Php Script 0.1.0 via the 'search' parameter. The payload uses a time-based blind SQLi technique to extract data from the database.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N