CVE-2023-31753
CRITICALeNdonesia 8.7 - SQL Injection via diskusi.php rid Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2023-31753. PoCs published by KIL0BYT3X.
AI-analyzed exploit summary This PoC demonstrates a SQL injection vulnerability in eNdonesia Portal v8.7 via the 'rid' parameter in diskusi.php, using a time-based payload to confirm exploitation.
Description
SQL injection vulnerability in diskusi.php in eNdonesia 8.7, allows an attacker to execute arbitrary SQL commands via the "rid=" parameter.
Exploits (2)
This PoC demonstrates a SQL injection vulnerability in eNdonesia Portal v8.7 via the 'rid' parameter in diskusi.php, using a time-based payload to confirm exploitation.
This repository contains a functional proof-of-concept for CVE-2023-31753, demonstrating a SQL injection vulnerability in eNdonesia Portal v8.7 via the 'rid' parameter in diskusi.php. The PoC includes a crafted HTTP request with a sleep payload to confirm the vulnerability.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H