CVE-2021-42670
CRITICALEngineers Online Portal - SQL Injection via Announcements Student ID Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2021-42670. PoCs published by 0xDeku.
AI-analyzed exploit summary This repository provides a proof-of-concept for CVE-2021-42670, an SQL injection vulnerability in the Engineers Online Portal system. The exploit targets the 'id' parameter in 'announcements_student.php' to extract sensitive data, such as the MySQL server version.
Description
A SQL injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the id parameter to the announcements_student.php web page. As a result a malicious user can extract sensitive data from the web server and in some cases use this vulnerability in order to get a remote code execution on the remote web server.
Exploits (2)
This repository provides a proof-of-concept for CVE-2021-42670, an SQL injection vulnerability in the Engineers Online Portal system. The exploit targets the 'id' parameter in 'announcements_student.php' to extract sensitive data, such as the MySQL server version.
This repository provides a technical description and proof-of-concept payload for an SQL Injection vulnerability in the Engineers Online Portal system, specifically targeting the 'id' parameter in 'announcements_student.php'. The PoC demonstrates how to extract the MySQL server version using a crafted SQL injection payload.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H