CVE-2024-37791
MEDIUMDuxCMS3 v3.1.3 - SQL Injection via Keyword Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-37791. PoCs published by czheisenberg.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2024-37791, a time-based blind SQL injection vulnerability in DuxCMS 3.1.3. It includes root cause analysis, vulnerable code snippets, and proof-of-concept payloads demonstrating the exploit.
Description
DuxCMS3 v3.1.3 was discovered to contain a SQL injection vulnerability via the keyword parameter at /article/Content/index?class_id.
Exploits (1)
This repository provides a detailed technical analysis of CVE-2024-37791, a time-based blind SQL injection vulnerability in DuxCMS 3.1.3. It includes root cause analysis, vulnerable code snippets, and proof-of-concept payloads demonstrating the exploit.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L