NexusPHP CVE-2017-12776 SQL Injection Vulnerability
BID:100596
Info
NexusPHP CVE-2017-12776 SQL Injection Vulnerability
| Bugtraq ID: | 100596 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-12776 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 18 2017 12:00AM |
| Updated: | Aug 18 2017 12:00AM |
| Credit: | Shiyan of Shepi Team |
| Vulnerable: |
NexusPHP NexusPHP 1.5 |
| Not Vulnerable: | |
Discussion
NexusPHP CVE-2017-12776 SQL Injection Vulnerability
NexusPHP is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
An attacker can exploit this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
NexusPHP 1.5 is affected; other versions may also be vulnerable.
NexusPHP is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied input before using it in an SQL query.
An attacker can exploit this issue to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
NexusPHP 1.5 is affected; other versions may also be vulnerable.
Exploit / POC
NexusPHP CVE-2017-12776 SQL Injection Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.