The code describes an SQL injection vulnerability in FAQMasterFlex 1.2, where the 'category_id' parameter in faq.php is vulnerable due to improper input sanitization. The PoC demonstrates the vulnerability but does not include executable exploit code.
Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:FAQMasterFlex 1.2
No auth needed
Prerequisites:Access to the vulnerable FAQMasterFlex installation