CVE-2019-25580
HIGHownDMS 4.7 SQL Injection via pdfstream.php imagestream.php
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25580. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary The exploit demonstrates SQL injection vulnerabilities in ownDMS 4.7 via multiple endpoints, including `pdfstream.php`, `imagestream.php`, and `cashbook.php`. The PoC includes crafted HTTP requests with URL-encoded SQL payloads that extract data or execute arbitrary SQL commands.
Description
ownDMS 4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the IMG parameter. Attackers can send GET requests to pdfstream.php, imagestream.php, or anyfilestream.php with crafted SQL payloads in the IMG parameter to extract sensitive database information including version and database names.
Exploits (1)
The exploit demonstrates SQL injection vulnerabilities in ownDMS 4.7 via multiple endpoints, including `pdfstream.php`, `imagestream.php`, and `cashbook.php`. The PoC includes crafted HTTP requests with URL-encoded SQL payloads that extract data or execute arbitrary SQL commands.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N