.. / CVE-2019-17418

Exploit for MetInfo 7.0.0 beta - SQL Injection (CVE-2019-17418)

Description:

MetInfo 7.0.0 beta is susceptible to SQL injection via the admin/?n=language&c=language_general&a=doSearchParameter appno parameter (a different issue than CVE-2019-16997).

Nuclei Template

View the template here CVE-2019-17418.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2019/CVE-2019-17418.yaml
Copy

References:

https://github.com/ARPSyndicate/cvemon
https://nvd.nist.gov/vuln/detail/CVE-2019-17418
https://github.com/0ps/pocassistdb
https://github.com/evi1code/Just-for-fun/issues/2
https://github.com/ARPSyndicate/kenzer-templates