Security
Headlines
HeadlinesLatestCVEs

Headline

eClass IP 2.5 SQL Injection

eClass IP version 2.5 suffers from a remote SQL injection vulnerability.

Packet Storm
#sql#xss#csrf#vulnerability#web#ios#mac#windows#apple#google#ubuntu#linux#debian#cisco#java#php#perl#auth#ruby#firefox

eClass IP 2.5 SQL Injection

Posted Oct 9, 2023

Authored by indoushka

eClass IP version 2.5 suffers from a remote SQL injection vulnerability.

tags | exploit, remote, sql injection

SHA-256 | b711babfc66671ea5103fe26d521747c60621f2c26be69bc9fb4ef7463b6da31

Download | Favorite | View

eClass IP 2.5 SQL Injection

====================================================================================================================================| # Title     : eClass IP 2.5 Sql injection Vulnerability                                                                          || # Author    : indoushka                                                                                                          || # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 69.0(32-bit)                                               | | # Vendor    : https://www.eclass.com.hk/en/product/eclass-ip/                                                                    |  ====================================================================================================================================poc :[+] Dorking İn Google Or Other Search Enggine.[+] use payload : /gallery_detail.php?cid=55&id=161 <===== inject here[+] http://127.0.0.www.cls.eduhk/tc/gallery_detail.php?cid=55&id=161[+] Panel : /templates/index.php?err=1&DirectLink= or /ad_min_man/login.phpGreetings to :=================================================================jericho * Larry W. Cashdollar * shadow_00715 * LiquidWorm * Hussin-X * D4NB4R |===============================================================================

File Tags

  • ActiveX (932)
  • Advisory (82,456)
  • Arbitrary (16,316)
  • BBS (2,859)
  • Bypass (1,764)
  • CGI (1,029)
  • Code Execution (7,343)
  • Conference (680)
  • Cracker (843)
  • CSRF (3,352)
  • DoS (23,623)
  • Encryption (2,372)
  • Exploit (52,159)
  • File Inclusion (4,230)
  • File Upload (977)
  • Firewall (821)
  • Info Disclosure (2,797)
  • Intrusion Detection (895)
  • Java (3,054)
  • JavaScript (865)
  • Kernel (6,760)
  • Local (14,525)
  • Magazine (586)
  • Overflow (12,775)
  • Perl (1,423)
  • PHP (5,156)
  • Proof of Concept (2,345)
  • Protocol (3,623)
  • Python (1,543)
  • Remote (30,920)
  • Root (3,598)
  • Rootkit (513)
  • Ruby (612)
  • Scanner (1,644)
  • Security Tool (7,912)
  • Shell (3,201)
  • Shellcode (1,216)
  • Sniffer (896)
  • Spoof (2,213)
  • SQL Injection (16,422)
  • TCP (2,417)
  • Trojan (687)
  • UDP (896)
  • Virus (666)
  • Vulnerability (31,915)
  • Web (9,732)
  • Whitepaper (3,753)
  • x86 (965)
  • XSS (18,011)
  • Other

File Archives

  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • Older

Systems

  • AIX (428)
  • Apple (2,026)
  • BSD (375)
  • CentOS (57)
  • Cisco (1,925)
  • Debian (6,858)
  • Fedora (1,692)
  • FreeBSD (1,246)
  • Gentoo (4,347)
  • HPUX (879)
  • iOS (358)
  • iPhone (108)
  • IRIX (220)
  • Juniper (69)
  • Linux (46,943)
  • Mac OS X (691)
  • Mandriva (3,105)
  • NetBSD (256)
  • OpenBSD (486)
  • RedHat (13,974)
  • Slackware (941)
  • Solaris (1,610)
  • SUSE (1,444)
  • Ubuntu (8,974)
  • UNIX (9,323)
  • UnixWare (186)
  • Windows (6,591)
  • Other

Packet Storm: Latest News

CUPS IPP Attributes LAN Remote Code Execution