This exploit demonstrates SQL injection vulnerabilities in SimpNews version 2.16.2 and below, targeting multiple parameters in different files to extract user credentials. The PoC includes crafted SQL queries to dump usernames and passwords from the database.
Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target:SimpNews version 2.16.2 and below
No auth needed
Prerequisites:Access to the vulnerable web application