my python poc CVE-2023-24774 and CVE-2023-24775 this sqli cve funadmin
# CVE-2023-24775-and-CVE-2023-24780
my python poc 2023-24780 and CVE-2023-24775 this sqli cve funadmin
This is a repository with a poc exploit for python cve sqli funadmin.
CVE-2023-24774 - https://nvd.nist.gov/vuln/detail/CVE-2023-24780
Vulnerable version of Funadmin v3.2.0
Vulnerability via id parameter in /databases/table/columns.
and
CVE-2023-24775 - https://nvd.nist.gov/vuln/detail/CVE-2023-24775
It was found, in Funadmin v3.2.0
This is implemented via the selectFields parameter in \member\Member.php.
run
1) python sqli_poc.py -u https://site.com
2) if CVE-2023-24780 enter 1, if CVE-2023-24775 enter 2
3) input sqli for example OR 1=1 or press entr program enters sqli for you
登录后查看神龙缓存的 POC 文件快照
登录查看