This exploit demonstrates a time-based SQL injection vulnerability in Nuevo Mailer version 6.0 and below via the 'r' parameter in the rdr.php script. The PoC uses a sleep function to confirm the vulnerability.
Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:Nuevo Mailer <= 6.0
No auth needed
Prerequisites:Access to the vulnerable rdr.php script