The provided text describes an SQL injection vulnerability in Cotonti 0.6.23, where the 'v' parameter in the URL is not properly sanitized. It includes a proof-of-concept URL demonstrating the vulnerability but lacks executable exploit code.
Classification
Writeup 80%
Attack Type
Sqli
Complexity
Trivial
Reliability
Theoretical
Target:Cotonti 0.6.23
No auth needed
Prerequisites:Access to the vulnerable Cotonti admin.php endpoint