Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2018-8820 PoC — Square 9 GlobalForms SQL注入漏洞

Source
Associated Vulnerability
Title: Square 9 GlobalForms SQL注入漏洞 (CVE-2018-8820)
Description:An issue was discovered in Square 9 GlobalForms 6.2.x. A Time Based SQL injection vulnerability in the "match" parameter allows remote authenticated attackers to execute arbitrary SQL commands. It is possible to upgrade access to full server compromise via xp_cmdshell. In some cases, the authentication requirement for the attack can be met by sending the default admin credentials.
Description
 PoC Exploit for CVE-2018-8820
Readme
![Supported Python versions](https://img.shields.io/badge/python-2.7-blue.svg)
# frevvomapexec
frevvomapexec is a script to verify the existence of a blind SQL injection vulnerability by injecting a delay of your choosing in seconds in Square 9 GlobalForms 6.2. To verify the vulnerability is legitimate, the end user will be required to do math (e.g. Subtracting the smaller number from the bigger number in seconds). If that math value aligns approximately with the parameter specified with (-s) you are the proud new owner of a SQL injection. Also, use SQLmap. It is your friend. Also, remember this is an authenticated SQL injection! But do not dispair oftentimes the server will still have default credentials enabled! By default freevomapexec uses the default credentials so oftentimes all is well!

## Usage ##
Usage: frevvomapexec.py [-h] -t TARGET -s SECONDS -o PORT [-u] [-p]

        Proof of Concept script for validation of CVE-2018-8820.
         - Type of issue: Authenticated Blind SQL injection
         - Product: Square 9 GlobalForms
         - Version: v6.2.x

##### Required: ##### 
    -t TARGET, --target TARGET        Target URL or IP Address
    -s SECONDS, --seconds SECONDS     Number of seconds to pause Frevvo
    -o PORT, --port PORT              Frevvo Web Server Port
  
##### Optional Arguments: #####
    -h, --help            show this help message and exit
    -u, --username        Login Username
    -p, --password        Login Password

File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →