mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-09 19:17:37 +02:00
34 lines
1.4 KiB
Markdown
34 lines
1.4 KiB
Markdown
### [CVE-2016-2555](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2555)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://github.com/atutor/ATutor/commit/629b2c992447f7670a2fecc484abfad8c4c2d298
|
|
- https://www.exploit-db.com/exploits/39514/
|
|
|
|
#### Github
|
|
- https://github.com/ARPSyndicate/cvemon
|
|
- https://github.com/BLACKHAT-SSG/OSWE-Preparation-
|
|
- https://github.com/MdTauheedAlam/AWAE-OSWE-Notes
|
|
- https://github.com/PwnAwan/OSWE-Preparation-
|
|
- https://github.com/R0B1NL1N/OSWE
|
|
- https://github.com/Xcod3bughunt3r/OSWE
|
|
- https://github.com/jrgdiaz/CVE-2016-2555
|
|
- https://github.com/kymb0/web_study
|
|
- https://github.com/maximilianmarx/atutor-blind-sqli
|
|
- https://github.com/mishmashclone/ManhNho-AWAE-OSWE
|
|
- https://github.com/mishmashclone/timip-OSWE
|
|
- https://github.com/shadofren/CVE-2016-2555
|
|
- https://github.com/shreyaschavhan/oswe-awae-pre-preperation-plan-and-notes
|
|
- https://github.com/svdwi/OSWE-Labs-Poc
|
|
- https://github.com/timip/OSWE
|
|
- https://github.com/zer0byte/AWAE-OSWP
|
|
|