CVE-2023-29849
HIGHBang Resto 1.0 - SQL Injection via btnMenuItemID, itemID, itemPrice, menuID, staffID, or itemqty Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-29849. PoCs published by Rahad Chowdhury.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Bang Resto v1.0 via the 'btnMenuItemID' parameter. It provides a step-by-step guide to exploit the vulnerability using a UNION-based SQL injection to extract user, database, and version information.
Description
Bang Resto 1.0 was discovered to contain multiple SQL injection vulnerabilities via the btnMenuItemID, itemID, itemPrice, menuID, staffID, or itemqty parameter.
Exploits (1)
This exploit demonstrates a SQL injection vulnerability in Bang Resto v1.0 via the 'btnMenuItemID' parameter. It provides a step-by-step guide to exploit the vulnerability using a UNION-based SQL injection to extract user, database, and version information.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H