The exploit demonstrates an unauthenticated SQL injection vulnerability in CommSy <= 8.6.5 via the 'cid' HTTP GET parameter, providing three proof-of-concept payloads (boolean-based blind, error-based, and time-based blind).
Classification
Working Poc 100%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:CommSy <= 8.6.5
No auth needed
Prerequisites:Access to the target web application