Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-24775 PoC — FunAdmin SQL注入漏洞

Source
Associated Vulnerability
Title: FunAdmin SQL注入漏洞 (CVE-2023-24775)
Description:Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \member\Member.php.
Description
my python poc CVE-2023-24774 and CVE-2023-24775 this sqli cve funadmin
Readme
# CVE-2023-24775-and-CVE-2023-24780
my python poc 2023-24780 and CVE-2023-24775 this sqli cve funadmin

This is a repository with a poc exploit for python cve sqli funadmin.

CVE-2023-24774 - https://nvd.nist.gov/vuln/detail/CVE-2023-24780

Vulnerable version of Funadmin v3.2.0 
Vulnerability via id parameter in /databases/table/columns.

and

CVE-2023-24775 - https://nvd.nist.gov/vuln/detail/CVE-2023-24775

It was found, in Funadmin v3.2.0 
This is implemented via the selectFields parameter in \member\Member.php.


run

1) python sqli_poc.py -u https://site.com
 
2) if CVE-2023-24780 enter 1, if CVE-2023-24775 enter 2
 
3) input sqli for example OR 1=1 or press entr program enters sqli for you
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →