Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-34327. PoCs published by 0xsu3ks.
AI-analyzed exploit summary This repository contains a functional Python script that checks for a time-based blind SQL injection vulnerability (CVE-2024-34327) in Sielox AnyWare 2.1.2 by sending a crafted POST request to the `/auth/password-reset-token.php` endpoint and measuring the response delay.
Description
Sielox AnyWare v2.1.2 was discovered to contain a SQL injection vulnerability via the email address field of the password reset form.
Exploits (1)
This repository contains a functional Python script that checks for a time-based blind SQL injection vulnerability (CVE-2024-34327) in Sielox AnyWare 2.1.2 by sending a crafted POST request to the `/auth/password-reset-token.php` endpoint and measuring the response delay.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N