Exploitation Summary
EIP tracks 2 public exploits for CVE-2023-46022. PoCs published by Ersin Erenler, ersinerenler.
AI-analyzed exploit summary This exploit demonstrates an Out-of-Band SQL Injection vulnerability in Blood Bank 1.0 via the 'bid' parameter in /delete.php. The payload uses the 'load_file' function to exfiltrate database and version information via a Burp Collaborator domain.
Description
SQL Injection vulnerability in delete.php in Code-Projects Blood Bank 1.0 allows attackers to run arbitrary SQL commands via the 'bid' parameter.
Exploits (2)
This exploit demonstrates an Out-of-Band SQL Injection vulnerability in Blood Bank 1.0 via the 'bid' parameter in /delete.php. The payload uses the 'load_file' function to exfiltrate database and version information via a Burp Collaborator domain.
The repository provides a functional proof-of-concept for CVE-2023-46022, demonstrating an Out-of-Band (OOB) SQL Injection vulnerability in Code-Projects Blood Bank 1.0 via the 'bid' parameter in /delete.php. The PoC includes a crafted payload and a detailed example request using Burp Collaborator to exfiltrate database and version information.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H