.. / CVE-2019-16997

Exploit for Metinfo 7.0.0 beta - SQL Injection (CVE-2019-16997)

Description:

Metinfo 7.0.0 beta is susceptible to SQL Injection in app/system/language/admin/language_general.class.php via the admin/?n=language&c=language_general&a=doExportPack appno parameter.

Nuclei Template

View the template here CVE-2019-16997.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2019/CVE-2019-16997.yaml
Copy

References:

https://github.com/XiaOkuoAi/XiaOkuoAi.github.io/issues/2
https://nvd.nist.gov/vuln/detail/CVE-2019-16997
https://github.com/jweny/pocassistdb
https://github.com/0ps/pocassistdb
https://github.com/zhibx/fscan-Intranet