CVE-2023-0912
MEDIUMAuto Dealer Management System 1.0 - SQL Injection via id Parameter in view_transaction Page
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-0912. PoCs published by Muhammad Navaid Zafar Ansari.
AI-analyzed exploit summary This exploit demonstrates a SQL Injection vulnerability in Auto Dealer Management System v1.0 via the 'id' parameter in the 'view_transaction.php' page. The PoC includes a crafted HTTP GET request that extracts database information, version, and user details.
Description
A vulnerability classified as critical has been found in SourceCodester Auto Dealer Management System 1.0. This affects an unknown part of the file /adms/admin/?page=vehicles/view_transaction. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-221481 was assigned to this vulnerability.
Exploits (1)
This exploit demonstrates a SQL Injection vulnerability in Auto Dealer Management System v1.0 via the 'id' parameter in the 'view_transaction.php' page. The PoC includes a crafted HTTP GET request that extracts database information, version, and user details.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L