module
SePortal SQLi Remote Code Execution
Disclosed | Created |
---|---|
2014-03-20 | 2018-05-30 |
Disclosed
2014-03-20
Created
2018-05-30
Description
This module exploits a vulnerability found in SePortal version 2.5.
When logging in as any non-admin user, it's possible to retrieve the admin session
from the database through SQL injection. The SQL injection vulnerability exists
in the "staticpages.php" page. This hash can be used to take over the admin
user session. After logging in, the "/admin/downloads.php" page will be used
to upload arbitrary code.
When logging in as any non-admin user, it's possible to retrieve the admin session
from the database through SQL injection. The SQL injection vulnerability exists
in the "staticpages.php" page. This hash can be used to take over the admin
user session. After logging in, the "/admin/downloads.php" page will be used
to upload arbitrary code.
Authors
jsass
xistence xistence@0x90.nl
xistence xistence@0x90.nl
Platform
PHP
Architectures
php
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.