Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-7410 PoC — WebsiteBaker SQL注入漏洞

Source
Associated Vulnerability
Title:WebsiteBaker SQL注入漏洞 (CVE-2017-7410)
Description:WebsiteBaker是WebsiteBaker组织负责维护开发的一套开源的PHP内容管理系统(CMS)。该系统支持所见即所得编辑器、搜索引擎优化和附加组件等。 WebsiteBaker 2.10.0及之前的版本中的account/signup.php和account/signup2.php文件存在SQL注入漏洞。远程攻击者可借助‘username’和‘display_name’参数利用该漏洞执行任意的SQL命令。
Description
To exploit SQL injection vulnerability
File Snapshot

[4.0K] /data/pocs/096b5684b93d092040ea5f9e704d5d72ed44a959 ├── [288K] it22327680_cve-2017-7410.pdf ├── [2.6K] signup.php ├── [ 26] Tryhackme Room link.txt └── [1.4K] users.sql 0 directories, 4 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.