Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-44542. PoCs published by sshipanoo.
AI-analyzed exploit summary The repository provides a technical description of a SQL injection vulnerability in todesk v1.1, specifically via the 'title' parameter in the '/news.html' endpoint. It includes a proof-of-concept URL demonstrating the exploit but lacks functional exploit code.
Description
SQL Injection vulnerability in todesk v.1.1 allows a remote attacker to execute arbitrary code via the /todesk.com/news.html parameter.
Exploits (1)
The repository provides a technical description of a SQL injection vulnerability in todesk v1.1, specifically via the 'title' parameter in the '/news.html' endpoint. It includes a proof-of-concept URL demonstrating the exploit but lacks functional exploit code.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H