CVE-2024-33288
HIGHPrison Management System Using PHP 1.0 - SQL Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-33288. PoCs published by Sanjay Singh.
AI-analyzed exploit summary This exploit demonstrates an SQL injection authentication bypass in the Prison Management System by injecting a tautology into the username field, allowing unauthorized admin access. The PoC provides clear steps to reproduce the vulnerability.
Description
Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the Admin login page.
Exploits (1)
This exploit demonstrates an SQL injection authentication bypass in the Prison Management System by injecting a tautology into the username field, allowing unauthorized admin access. The PoC provides clear steps to reproduce the vulnerability.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L