Netartmedia Event Portal Time-Based Blind SQL Injection Vulnerability

Vulnerability

A time-based blind SQL injection vulnerability has been identified in Netartmedia Event Portal version 2.0. This vulnerability allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Exploitation involves sending POST requests to loginaction.php with malicious SQL payloads in the Email field, enabling attackers to extract sensitive database information.

Impact

Exploitation of this vulnerability allows for time-based blind SQL injection, where an attacker can manipulate SQL queries and potentially extract sensitive information from the database.

Reproduction

To reproduce this vulnerability, send a POST request to loginaction.php with a payload injected into the Email parameter. The payload should be crafted to exploit the SQL injection vulnerability, such as by using a SQL injection payload that includes a time-based delay, indicating successful exploitation.

Added: Mar 12, 2026, 4:21 PM
Updated: Mar 12, 2026, 4:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
3.8
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.