Exploitation Summary
EIP tracks 2 public exploits for CVE-2023-29809. PoCs published by Lucas Noki (0xPrototype), zPrototype.
AI-analyzed exploit summary This exploit demonstrates a time-based SQL injection vulnerability in Cmaps v8.0 via the `bookmap` parameter. The PoC uses a sleep-based payload to confirm the vulnerability and suggests using sqlmap for further exploitation.
Description
SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbitrary code via a crafted script in the request.
Exploits (2)
This exploit demonstrates a time-based SQL injection vulnerability in Cmaps v8.0 via the `bookmap` parameter. The PoC uses a sleep-based payload to confirm the vulnerability and suggests using sqlmap for further exploitation.
This repository contains a proof-of-concept for an unauthenticated SQL injection vulnerability in the `bookmap` parameter of the cmaps software. The exploit demonstrates time-based SQL injection using a sleep payload and provides steps to reproduce and dump the database using sqlmap.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H