This exploit demonstrates a SQL injection vulnerability in CMS snews. The PoC provides a URL with a crafted SQL query that extracts user credentials from the database by manipulating the 'id' parameter.
Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:CMS snews
No auth needed
Prerequisites:Access to the vulnerable snews.php endpoint