Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-37076. PoCs published by BKpatron.
AI-analyzed exploit summary This exploit demonstrates SQL injection in Victor CMS 1.0 via the 'post' parameter in post.php. It includes payloads for boolean-based blind, error-based, time-based blind, and UNION-based SQLi techniques.
Description
Victor CMS version 1.0 contains a SQL injection vulnerability in the 'post' parameter on post.php that allows remote attackers to manipulate database queries. Attackers can exploit this vulnerability by sending crafted UNION SELECT payloads to extract database information through boolean-based, error-based, and time-based injection techniques.
Exploits (1)
This exploit demonstrates SQL injection in Victor CMS 1.0 via the 'post' parameter in post.php. It includes payloads for boolean-based blind, error-based, time-based blind, and UNION-based SQLi techniques.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N