This exploit demonstrates a SQL injection vulnerability in mySeatXT 0.1781, allowing arbitrary data extraction and potential PHP shell creation via the 'autocomplete.php' endpoint. The PoC injects a PHP system command into a SQL query, writing a shell to a web-accessible directory.
Classification
Working Poc 90%
Target:
mySeatXT 0.1781
No auth needed
Prerequisites:
Access to the 'autocomplete.php' endpoint · Write permissions to the web directory