CVE-2024-27746
CRITICALPetrol Pump Mangement Software <1.0 - SQL Injection
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2024-27746. PoCs published by Shubham Pandey, shubham-s-pandey.
AI-analyzed exploit summary This exploit demonstrates a time-based SQL injection vulnerability in Petrol Pump Management Software v1.0. The PoC uses a crafted email parameter to inject a SLEEP command, confirming the vulnerability via delayed page load.
Description
SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email address parameter in the index.php component.
Exploits (2)
This exploit demonstrates a time-based SQL injection vulnerability in Petrol Pump Management Software v1.0. The PoC uses a crafted email parameter to inject a SLEEP command, confirming the vulnerability via delayed page load.
The repository contains detailed technical writeups for multiple CVEs affecting Petrol Pump Management Software and Employee Management System, including SQL injection, XSS, and file upload vulnerabilities. Each writeup provides specific attack vectors, affected components, and payload examples.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H