CVE-2023-33592
CRITICALLost and Found Information System v1.0 - SQL Injection
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2023-33592. PoCs published by Amirhossein Bahramizadeh, ChineseOldboy.
AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Lost and Found Information System v1.0 by injecting a payload that bypasses authentication. The payload checks for the presence of 'admin' in the response to confirm successful exploitation.
Description
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/contact_information.
Exploits (2)
This exploit demonstrates a SQL injection vulnerability in Lost and Found Information System v1.0 by injecting a payload that bypasses authentication. The payload checks for the presence of 'admin' in the response to confirm successful exploitation.
This repository contains a Python script that scans for SQL injection vulnerabilities in a specific endpoint. It reads URLs from a file and tests for SQLi by appending a basic SQL injection payload.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H