Exploitation Summary
EIP tracks 1 public exploit for CVE-2023-46021. PoCs published by ersinerenler.
AI-analyzed exploit summary The repository provides a functional proof-of-concept for CVE-2023-46021, demonstrating an Out-of-Band (OOB) SQL Injection vulnerability in Code-Projects Blood Bank 1.0 via the 'reqid' parameter in /cancel.php. The PoC includes a crafted payload and a sample HTTP request to exploit the vulnerability using Burp Collaborator.
Description
SQL Injection vulnerability in cancel.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary commands via the 'reqid' parameter.
Exploits (1)
The repository provides a functional proof-of-concept for CVE-2023-46021, demonstrating an Out-of-Band (OOB) SQL Injection vulnerability in Code-Projects Blood Bank 1.0 via the 'reqid' parameter in /cancel.php. The PoC includes a crafted payload and a sample HTTP request to exploit the vulnerability using Burp Collaborator.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N