CVE-2023-0915
MEDIUMAuto Dealer Management System 1.0 - SQL Injection via Manage User ID Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-0915. PoCs published by Muhammad Navaid Zafar Ansari.
AI-analyzed exploit summary This exploit demonstrates a SQL Injection vulnerability in Auto Dealer Management System v1.0 via the 'id' parameter in manage_user.php. The PoC includes a crafted HTTP GET request that extracts database information such as user credentials, database directory, and database name.
Description
A vulnerability classified as critical has been found in SourceCodester Auto Dealer Management System 1.0. Affected is an unknown function of the file /adms/admin/?page=user/manage_user. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-221490 is the identifier assigned to this vulnerability.
Exploits (1)
This exploit demonstrates a SQL Injection vulnerability in Auto Dealer Management System v1.0 via the 'id' parameter in manage_user.php. The PoC includes a crafted HTTP GET request that extracts database information such as user credentials, database directory, and database name.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L