CVE-2016-2555
CRITICALATutor 2.2.1 - SQL Injection via searchFriends Function
Title source: llmExploitation Summary
EIP tracks 6 public exploits for CVE-2016-2555.
PoCs published by Metasploit, shadofren, maximilianmarx, including Metasploit module exploits/linux/http/atutor_filemanager_traversal.
AI-analyzed exploit summary This Metasploit module exploits a SQL injection vulnerability (CVE-2016-2555) in ATutor 2.2.1, allowing authentication bypass and remote code execution via malicious plugin upload. It leverages a SQLi in the social connections search feature to extract admin credentials and uploads a PHP payload.
Description
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php.
Exploits (6)
This Metasploit module exploits a SQL injection vulnerability (CVE-2016-2555) in ATutor 2.2.1, allowing authentication bypass and remote code execution via malicious plugin upload. It leverages a SQLi in the social connections search feature to extract admin credentials and uploads a PHP payload.
This repository contains a functional exploit for CVE-2016-2555, targeting ATutor. The exploit demonstrates an authentication bypass via type juggling, password reset, and arbitrary file upload leading to remote code execution.
This repository contains a functional Python script that exploits a blind SQL injection vulnerability in ATutor v2.2.1 (CVE-2016-2555). The script automates the enumeration and dumping of the underlying database by leveraging content-length differences in HTTP responses.
This repository contains a functional exploit for CVE-2016-2555, targeting ATutor 2.2.1. It combines SQL injection to extract credentials and a pass-the-hash attack to bypass authentication, followed by a ZIP file upload to achieve remote code execution.
This Metasploit module exploits a directory traversal vulnerability in ATutor 2.2.1, allowing remote code execution by uploading a malicious ZIP file. It also includes authentication bypass techniques via type juggling and TOCTOU vulnerabilities.
This Metasploit module exploits a SQL injection vulnerability (CVE-2016-2555) in ATutor 2.2.1 to bypass authentication, dump administrator credentials, and achieve remote code execution by uploading a malicious PHP plugin.
References (5)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H