Exploitation Summary
EIP tracks 1 public exploit for CVE-2022-50895. PoCs published by nu11secur1ty.
AI-analyzed exploit summary This exploit demonstrates SQL injection vulnerabilities in Aero CMS v0.0.1 via the 'author' parameter, including boolean-based blind, error-based, time-based blind, and UNION query techniques. The payloads are designed to extract database information or execute arbitrary SQL commands.
Description
Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, time-based, and UNION query techniques to extract sensitive database information and potentially compromise the system.
Exploits (1)
This exploit demonstrates SQL injection vulnerabilities in Aero CMS v0.0.1 via the 'author' parameter, including boolean-based blind, error-based, time-based blind, and UNION query techniques. The payloads are designed to extract database information or execute arbitrary SQL commands.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H