CVE-2017-20139 Information
Jul 24, 2022
cve
Description
A vulnerability was found in Itech Movie Portal Script 7.36. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /show_news.php. The manipulation of the argument id with the input AND (SELECT 1222 FROM(SELECT COUNT()CONCAT(0x71786b7a71(SELECT (ELT(1222=12221)))0x717a627871FLOOR(RAND(0)2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a) leads to sql injection (Error). The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Reference
https://www.exploit-db.com/exploits/41155/ https://vuldb.com/?id.96253
Share on: