CVE-2024-39250
CRITICAL NUCLEIEfroTech Timetrax v8.3 - Unauthenticated SQL Injection via Search q Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-39250. PoCs published by efrann. A Nuclei detection template is also available.
AI-analyzed exploit summary The repository contains a Nuclei template for detecting an unauthenticated SQL Injection vulnerability in TimeTrax. The template sends a crafted GET request to '/search.aspx?q=' and checks for a specific error message and HTTP 500 status code.
Description
EfroTech Timetrax v8.3 was discovered to contain an unauthenticated SQL injection vulnerability via the q parameter in the search web interface.
Exploits (1)
The repository contains a Nuclei template for detecting an unauthenticated SQL Injection vulnerability in TimeTrax. The template sends a crafted GET request to '/search.aspx?q=' and checks for a specific error message and HTTP 500 status code.
Nuclei Templates (1)
icon_hash="-661694518"
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H