mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-27 02:02:23 +02:00
25 lines
1.0 KiB
Markdown
25 lines
1.0 KiB
Markdown
### [CVE-2021-28419](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28419)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
The "order_col" parameter in archive.php of SEO Panel 4.8.0 is vulnerable to time-based blind SQL injection, which leads to the ability to retrieve all databases.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- http://packetstormsecurity.com/files/162322/SEO-Panel-4.8.0-SQL-Injection.html
|
|
- https://github.com/seopanel/Seo-Panel/issues/209
|
|
|
|
#### Github
|
|
- https://github.com/2lambda123/CVE-mitre
|
|
- https://github.com/2lambda123/Windows10Exploits
|
|
- https://github.com/ARPSyndicate/cvemon
|
|
- https://github.com/Offensive-Penetration-Security/OPSEC-Hall-of-fame
|
|
- https://github.com/nu11secur1ty/CVE-mitre
|
|
- https://github.com/nu11secur1ty/CVE-nu11secur1ty
|
|
- https://github.com/nu11secur1ty/Windows10Exploits
|
|
|