Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-25416. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This is a functional SQL injection exploit for AiOPMSD Final 1.0.0, demonstrating multiple vulnerable parameters across different PHP scripts. The payload extracts database information, user credentials, and version details via error-based SQLi techniques.
Description
AiOPMSD Final 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the country parameter. Attackers can send GET requests to country.php with crafted SQL payloads in the country parameter to extract sensitive database information including usernames, database names, and version details.
Exploits (1)
This is a functional SQL injection exploit for AiOPMSD Final 1.0.0, demonstrating multiple vulnerable parameters across different PHP scripts. The payload extracts database information, user credentials, and version details via error-based SQLi techniques.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N