CVE-2019-25726
HIGHAll in One Video Downloader 1.2 SQL Injection via admin page-edit
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25726. PoCs published by Deyaa Muhammad.
AI-analyzed exploit summary The exploit demonstrates a SQL injection vulnerability in All in One Video Downloader 1.2 via the 'id' parameter in the admin panel. It uses a UNION-based SQLi to extract database information such as user, database name, and version.
Description
All in One Video Downloader 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send requests to the admin interface with UNION-based SQL injection payloads in the id parameter to extract sensitive database information including usernames, databases, and version details.
Exploits (1)
The exploit demonstrates a SQL injection vulnerability in All in One Video Downloader 1.2 via the 'id' parameter in the admin panel. It uses a UNION-based SQLi to extract database information such as user, database name, and version.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N