my python poc 2023-24780 and CVE-2023-24775 this sqli cve funadmin
This is a repository with a poc exploit for python cve sqli funadmin.
CVE-2023-24774 - https://nvd.nist.gov/vuln/detail/CVE-2023-24780
Vulnerable version of Funadmin v3.2.0 Vulnerability via id parameter in /databases/table/columns.
and
CVE-2023-24775 - https://nvd.nist.gov/vuln/detail/CVE-2023-24775
It was found, in Funadmin v3.2.0 This is implemented via the selectFields parameter in \member\Member.php.
run
-
python sqli_poc.py -u https://site.com
-
if CVE-2023-24780 enter 1, if CVE-2023-24775 enter 2
-
input sqli for example OR 1=1 or press entr program enters sqli for you